2026 CVE Vulnerabilities

50,971 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8487HIGH7.5Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da...
CVE-2026-8486HIGH7.5Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Floodin...
CVE-2026-5783HIGH7.6Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Sof...
CVE-2026-39047HIGH7.5Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin...
CVE-2026-8485HIGH7.5Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i...
CVE-2026-8469HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic...
CVE-2026-22554HIGH7.8MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
CVE-2026-5946HIGH7.5Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`...
CVE-2026-45584HIGH8.1Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
CVE-2026-45498HIGH7.5Microsoft Defender Denial of Service Vulnerability
CVE-2026-42834HIGH7.8Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-42383HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme...
CVE-2026-41091HIGH7.8Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el...
CVE-2026-3039HIGH7.5BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory ...
CVE-2026-29518HIGH7Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that ...
CVE-2026-22315HIGH7.2Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component ...
CVE-2026-0856HIGH7.8Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables...
CVE-2026-9064HIGH7.5A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an uppe...
CVE-2026-44933HIGH8.5`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i...
CVE-2026-42959HIGH7.5NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that...
CVE-2026-42944HIGH7.5NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when enco...
CVE-2026-41292HIGH7.5NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsin...
CVE-2026-41054HIGH7.8In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/ent...
CVE-2026-40622HIGH7.5NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of a...
CVE-2026-5200HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now