2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42832 | MEDIUM | 5.5 | 0.2% | May 12, 2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-42830 | MEDIUM | 6.5 | 0.5% | May 12, 2026 | Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2026-42541 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG... |
| CVE-2026-42303 | MEDIUM | 6.1 | 0.3% | May 12, 2026 | Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s... |
| CVE-2026-42177 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-... |
| CVE-2026-42175 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu... |
| CVE-2026-42045 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ... |
| CVE-2026-41614 | MEDIUM | 6.2 | 0.4% | May 12, 2026 | Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-41612 | MEDIUM | 5.5 | 0.5% | May 12, 2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. |
| CVE-2026-41610 | MEDIUM | 5 | 0.6% | May 12, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una... |
| CVE-2026-41513 | MEDIUM | 4.8 | 0.3% | May 12, 2026 | Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec... |
| CVE-2026-41102 | MEDIUM | 5.5 | 0.3% | May 12, 2026 | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
| CVE-2026-41101 | MEDIUM | 5.5 | 0.3% | May 12, 2026 | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
| CVE-2026-41100 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. |
| CVE-2026-41097 | MEDIUM | 6.7 | 1.4% | May 12, 2026 | Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security... |
| CVE-2026-40421 | MEDIUM | 4.3 | 0.6% | May 12, 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose... |
| CVE-2026-40416 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-40380 | MEDIUM | 6.2 | 0.5% | May 12, 2026 | Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi... |
| CVE-2026-40374 | MEDIUM | 6.5 | 0.9% | May 12, 2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i... |
| CVE-2026-35440 | MEDIUM | 5.5 | 0.4% | May 12, 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose... |
| CVE-2026-35429 | MEDIUM | 4.3 | 0.5% | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-35423 | MEDIUM | 5.4 | 0.7% | May 12, 2026 | Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-35422 | MEDIUM | 6.5 | 0.6% | May 12, 2026 | Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec... |
| CVE-2026-35419 | MEDIUM | 5.5 | 0.4% | May 12, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2026-34663 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now