2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57104HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an...
CVE-2026-56179HIGH8.3Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing...
CVE-2026-56174HIGH7.8Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-54984HIGH7.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CVE-2026-54981HIGH7.8Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized...
CVE-2026-54123MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac...
CVE-2026-54113HIGH7.5Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o...
CVE-2026-50516CRITICAL9.4Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-50472HIGH7Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CVE-2026-49179HIGH8.8Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a...
CVE-2026-48483MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp...
CVE-2026-48446MEDIUM5.5CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
CVE-2026-48445MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48444MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48443MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48442HIGH7.1CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
CVE-2026-48440HIGH8.1ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th...
CVE-2026-48439HIGH7.5CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48438HIGH7.5CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application deni...
CVE-2026-48437MEDIUM5.5CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security ...
CVE-2026-48436MEDIUM6.5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...
CVE-2026-48435MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-48434MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48387MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48386HIGH7.5ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now