2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35419 | MEDIUM | 5.5 | 0.4% | May 12, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
| CVE-2026-34663 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis... |
| CVE-2026-34662 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result... |
| CVE-2026-34350 | MEDIUM | 6.5 | 0.8% | May 12, 2026 | Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw... |
| CVE-2026-34339 | MEDIUM | 5.5 | 0.3% | May 12, 2026 | Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny s... |
| CVE-2026-32209 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l... |
| CVE-2026-32185 | MEDIUM | 5.5 | 0.5% | May 12, 2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi... |
| CVE-2026-32175 | MEDIUM | 4.3 | 0.7% | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully... |
| CVE-2026-32170 | MEDIUM | 6.7 | 0.3% | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
| CVE-2026-31245 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori... |
| CVE-2026-31244 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo... |
| CVE-2026-31243 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio... |
| CVE-2026-31241 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo... |
| CVE-2026-25690 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec... |
| CVE-2026-21530 | MEDIUM | 6.7 | 0.3% | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
| CVE-2026-8407 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add... |
| CVE-2026-40300 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move... |
| CVE-2026-25431 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security ... |
| CVE-2026-20914 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User App... |
| CVE-2026-20905 | MEDIUM | 6.6 | 0.1% | May 12, 2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Appl... |
| CVE-2026-20881 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications m... |
| CVE-2026-20782 | MEDIUM | 6.6 | 0.1% | May 12, 2026 | Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications ... |
| CVE-2026-20772 | MEDIUM | 6.7 | 0.1% | May 12, 2026 | Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.... |
| CVE-2026-20771 | MEDIUM | 6.1 | 0.1% | May 12, 2026 | Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Appl... |
| CVE-2026-20754 | MEDIUM | 6.9 | 0.1% | May 12, 2026 | Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now