2026 CVE Vulnerabilities

48,611 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40376HIGH8.1Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40371HIGH8.8Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized...
CVE-2026-34335HIGH7Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca...
CVE-2026-34183HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P...
CVE-2026-34181HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base...
CVE-2026-34180HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ...
CVE-2026-33828HIGH7.8Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
CVE-2026-32193HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all...
CVE-2026-24181HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes...
CVE-2026-24180HIGH7.3NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes...
CVE-2026-22926HIGH7.8Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0419HIGH8Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u...
CVE-2026-0411HIGH8An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected...
CVE-2026-49948HIGH8.6Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s...
CVE-2026-24065HIGH8.1Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile...
CVE-2026-24064HIGH7.8Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC...
CVE-2026-10727HIGH7.2An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut...
CVE-2026-9279HIGH8.7Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t...
CVE-2026-52907HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change...
CVE-2026-52906HIGH7.7In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep...
CVE-2026-47899HIGH8.7The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with...
CVE-2026-46332HIGH8In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu...
CVE-2026-46330HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r...
CVE-2026-46328HIGH7.3In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp...
CVE-2026-46327HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now