2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35419MEDIUM5.5Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34663MEDIUM5.5Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis...
CVE-2026-34662MEDIUM5.5Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result...
CVE-2026-34350MEDIUM6.5Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw...
CVE-2026-34339MEDIUM5.5Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny s...
CVE-2026-32209MEDIUM4.4Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l...
CVE-2026-32185MEDIUM5.5Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi...
CVE-2026-32175MEDIUM4.3A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully...
CVE-2026-32170MEDIUM6.7Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-31245MEDIUM5.3The mem0 1.0.0 server lacks authentication and authorization controls for its memory creation API endpoint (POST /memori...
CVE-2026-31244MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo...
CVE-2026-31243MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio...
CVE-2026-31241MEDIUM6.5The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo...
CVE-2026-25690MEDIUM6.5An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec...
CVE-2026-21530MEDIUM6.7Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-8407MEDIUM4.3Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add...
CVE-2026-40300MEDIUM6.5Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move...
CVE-2026-25431MEDIUM5.3Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security ...
CVE-2026-20914MEDIUM5.5Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User App...
CVE-2026-20905MEDIUM6.6Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Appl...
CVE-2026-20881MEDIUM5.5Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications m...
CVE-2026-20782MEDIUM6.6Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications ...
CVE-2026-20772MEDIUM6.7Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121....
CVE-2026-20771MEDIUM6.1Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Appl...
CVE-2026-20754MEDIUM6.9Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denia...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now