2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42830MEDIUM6.5Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42825HIGH7Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42823CRITICAL9.9Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42541MEDIUM4.3Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG...
CVE-2026-42348HIGH7.5OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses ...
CVE-2026-42303MEDIUM6.1Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s...
CVE-2026-42300CRITICAL9.3DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc...
CVE-2026-42177MEDIUM5.3linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-...
CVE-2026-42175MEDIUM6.5requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu...
CVE-2026-42141HIGH7.7Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-42048CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to...
CVE-2026-42045MEDIUM6.2LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-41895HIGH7.5changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches ...
CVE-2026-41614MEDIUM6.2Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41613HIGH8.8Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41612MEDIUM5.5Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41611LOW3.3Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz...
CVE-2026-41610MEDIUM5Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una...
CVE-2026-41513MEDIUM4.8Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec...
CVE-2026-41109HIGH8.8Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and...
CVE-2026-41107HIGH7.4External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf...
CVE-2026-41103CRITICAL9.1Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho...
CVE-2026-41102MEDIUM5.5Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
CVE-2026-41101MEDIUM5.5Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
CVE-2026-41100MEDIUM4.4Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now