2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48434MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48387MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48386HIGH7.5ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure...
CVE-2026-48385HIGH7.7ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ...
CVE-2026-48384MEDIUM4.9ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi...
CVE-2026-48376MEDIUM5.4is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. ...
CVE-2026-48375MEDIUM6.5ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service...
CVE-2026-48362CRITICAL10ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ...
CVE-2026-47922MEDIUM4.7CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege...
CVE-2026-47704HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can...
CVE-2026-47299HIGH7.2Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut...
CVE-2026-47285MEDIUM6.5Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau...
CVE-2026-43606HIGH8.5Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local acce...
CVE-2026-42976HIGH7.8Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca...
CVE-2026-40375MEDIUM6.5Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
CVE-2026-39452MEDIUM6.3Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applicatio...
CVE-2026-35502MEDIUM4.6Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Appli...
CVE-2026-34635HIGH8.4is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low...
CVE-2026-34175MEDIUM5.4Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User...
CVE-2026-32791MEDIUM5.4Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring...
CVE-2026-32788MEDIUM5.4Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring...
CVE-2026-32677MEDIUM5.4Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an esca...
CVE-2026-28757MEDIUM5.4Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may...
CVE-2026-28729LOW2.4Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw...
CVE-2026-28707MEDIUM5.4Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escala...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now