2026 CVE Vulnerabilities
50,301 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27299 | MEDIUM | 6.3 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead ... |
| CVE-2026-34370 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains ... |
| CVE-2026-34213 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.7... |
| CVE-2026-34212 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralizati... |
| CVE-2026-33193 | MEDIUM | 4.6 | 0.2% | Apr 14, 2026 | Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a store... |
| CVE-2026-33146 | MEDIUM | 4.3 | 0.3% | Apr 14, 2026 | Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions ... |
| CVE-2026-34161 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting... |
| CVE-2026-25133 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros... |
| CVE-2026-25125 | MEDIUM | 4.9 | 0.3% | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side... |
| CVE-2026-27222 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application... |
| CVE-2026-34625 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-34624 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-34623 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-5754 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to i... |
| CVE-2026-34614 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. I... |
| CVE-2026-33829 | MEDIUM | 4.3 | 3.4% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to p... |
| CVE-2026-33822 | MEDIUM | 6.1 | 0.4% | Apr 14, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-33103 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information lo... |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.5% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an ... |
| CVE-2026-32223 | MEDIUM | 6.8 | 0.5% | Apr 14, 2026 | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a phys... |
| CVE-2026-32220 | MEDIUM | 4.4 | 0.3% | Apr 14, 2026 | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a... |
| CVE-2026-32218 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-32217 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-32216 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. |
| CVE-2026-32215 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now