2026 CVE Vulnerabilities

48,542 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42832MEDIUM5.5Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42830MEDIUM6.5Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42541MEDIUM4.3Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG...
CVE-2026-42303MEDIUM6.1Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s...
CVE-2026-42177MEDIUM5.3linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-...
CVE-2026-42175MEDIUM6.5requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu...
CVE-2026-42045MEDIUM6.2LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-41614MEDIUM6.2Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41612MEDIUM5.5Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41610MEDIUM5Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una...
CVE-2026-41513MEDIUM4.8Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec...
CVE-2026-41102MEDIUM5.5Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
CVE-2026-41101MEDIUM5.5Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
CVE-2026-41100MEDIUM4.4Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-41097MEDIUM6.7Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security...
CVE-2026-40421MEDIUM4.3Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose...
CVE-2026-40416MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-40380MEDIUM6.2Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi...
CVE-2026-40374MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i...
CVE-2026-35440MEDIUM5.5Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose...
CVE-2026-35429MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-35423MEDIUM5.4Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-35422MEDIUM6.5Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec...
CVE-2026-35419MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34663MEDIUM5.5Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now