2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33837 | HIGH | 7.8 | 1.8% | May 12, 2026 | Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33835 | HIGH | 7.8 | 2.1% | May 12, 2026 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33834 | HIGH | 7.8 | 0.3% | May 12, 2026 | Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33833 | HIGH | 8.2 | 0.5% | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Lear... |
| CVE-2026-33821 | CRITICAL | 9.9 | 0.7% | May 12, 2026 | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi... |
| CVE-2026-33117 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path... |
| CVE-2026-33112 | HIGH | 8.8 | 2.1% | May 12, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-33110 | HIGH | 8.8 | 2.0% | May 12, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-32209 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l... |
| CVE-2026-32204 | HIGH | 7.8 | 0.3% | May 12, 2026 | External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally... |
| CVE-2026-32185 | MEDIUM | 5.5 | 0.5% | May 12, 2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi... |
| CVE-2026-32177 | HIGH | 7.3 | 0.6% | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-32175 | MEDIUM | 4.3 | 0.7% | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully... |
| CVE-2026-32170 | MEDIUM | 6.7 | 0.3% | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32161 | HIGH | 7.5 | 0.3% | May 12, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Minip... |
| CVE-2026-31245 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori... |
| CVE-2026-31244 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo... |
| CVE-2026-31243 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio... |
| CVE-2026-31242 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via... |
| CVE-2026-31241 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo... |
| CVE-2026-31240 | HIGH | 7.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical ... |
| CVE-2026-31239 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-train... |
| CVE-2026-31238 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe... |
| CVE-2026-31237 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ... |
| CVE-2026-31236 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now