2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4017HIGH7.4Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause ...
CVE-2026-48368HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48365HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48309HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47968HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47967HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47642HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-47295HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-47290HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45756HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until...
CVE-2026-45077HIGH8.6Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45074HIGH8.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.1...
CVE-2026-59886HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon...
CVE-2026-59885HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER a...
CVE-2026-59884HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses lo...
CVE-2026-59200HIGH7.5Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib...
CVE-2026-59197HIGH8.2Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bo...
CVE-2026-58640HIGH7.8Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-58636HIGH7.8Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to ele...
CVE-2026-58635HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows a...
CVE-2026-58631HIGH7.8Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-58618HIGH7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-58610HIGH7.8Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally...
CVE-2026-58609HIGH7.8Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-58608HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now