2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41928MEDIUM6.9Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated...
CVE-2026-41105HIGH8.1Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove...
CVE-2026-40214MEDIUM6.3In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th...
CVE-2026-40213HIGH7.4OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un...
CVE-2026-35435CRITICAL10Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges ...
CVE-2026-35428CRITICAL9.6Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unaut...
CVE-2026-34327HIGH8.2Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac...
CVE-2026-33844CRITICAL9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-33823MEDIUM6.5Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-33111HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all...
CVE-2026-33109CRITICAL9.9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-32207MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an...
CVE-2026-26164HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-26129HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-8098HIGH7.3A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the ...
CVE-2026-8097MEDIUM6.3A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the fi...
CVE-2026-44365——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-34429. Reason: This candidate is a ...
CVE-2026-42449HIGH8.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve...
CVE-2026-42047HIGH8.6Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche...
CVE-2026-41692MEDIUM4.7i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes....
CVE-2026-41691CRITICAL9.1Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat...
CVE-2026-8142MEDIUM6.5VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use...
CVE-2026-8088MEDIUM5.5A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the ...
CVE-2026-8087HIGH7.8A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm...
CVE-2026-43510MEDIUM5.9manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now