2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48581HIGH7.8Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca...
CVE-2026-48572HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer all...
CVE-2026-48571HIGH7Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-48564HIGH8.8Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
CVE-2026-47632HIGH8.8Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adj...
CVE-2026-47296HIGH7.5Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-45646HIGH7.5Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove...
CVE-2026-44806HIGH7.5Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to ...
CVE-2026-44800HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification...
CVE-2026-42982HIGH7.8Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p...
CVE-2026-42975HIGH8.8Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja...
CVE-2026-42900HIGH8.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows ...
CVE-2026-40400HIGH8Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-40378HIGH7.5Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau...
CVE-2026-15703HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn...
CVE-2026-15429HIGH8.8A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling...
CVE-2026-15428HIGH8.8An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na...
CVE-2026-15427HIGH8.1An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf...
CVE-2026-9636HIGH8.2A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Secu...
CVE-2026-9292HIGH8.4A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability ste...
CVE-2026-9128HIGH7.3A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External...
CVE-2026-9127HIGH7.3A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con...
CVE-2026-60081HIGH7.5DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump file...
CVE-2026-59841HIGH7.5A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7....
CVE-2026-59835HIGH8.6A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now