2026 CVE Vulnerabilities

69,831 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23669HIGH8.8Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
CVE-2026-23668HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2026-23667HIGH7Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
CVE-2026-23665HIGH7.8Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
CVE-2026-23664HIGH7.5Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke...
CVE-2026-23662HIGH7.5Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati...
CVE-2026-23661HIGH7.5Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose inform...
CVE-2026-23660HIGH7.8Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally...
CVE-2026-23656MEDIUM5.9Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof...
CVE-2026-23654HIGH8.8Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to...
CVE-2026-23240CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() ...
CVE-2026-23239HIGH7.8In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() T...
CVE-2026-22629LOW3.7An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4...
CVE-2026-22628MEDIUM6.7An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a...
CVE-2026-22627HIGH8.8A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1....
CVE-2026-22614MEDIUM6.1The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a...
CVE-2026-22572HIGH7.2An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,...
CVE-2026-21791LOW3.3HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica...
CVE-2026-21262HIGH8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20967HIGH8.8Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a...
CVE-2026-1286MEDIUM6.5CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an...
CVE-2026-1261HIGH7.2The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions u...
CVE-2026-3585HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15....
CVE-2026-30927MEDIUM5.4Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event par...
CVE-2026-30925HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now