2026 CVE Vulnerabilities
50,357 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34623 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-5754 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to i... |
| CVE-2026-34614 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. I... |
| CVE-2026-33829 | MEDIUM | 4.3 | 3.4% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to p... |
| CVE-2026-33822 | MEDIUM | 6.1 | 0.4% | Apr 14, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-33103 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information lo... |
| CVE-2026-32226 | MEDIUM | 5.9 | 0.5% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an ... |
| CVE-2026-32223 | MEDIUM | 6.8 | 0.5% | Apr 14, 2026 | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a phys... |
| CVE-2026-32220 | MEDIUM | 4.4 | 0.3% | Apr 14, 2026 | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a... |
| CVE-2026-32218 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-32217 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-32216 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. |
| CVE-2026-32215 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information... |
| CVE-2026-32214 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca... |
| CVE-2026-32212 | MEDIUM | 5.5 | 0.3% | Apr 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize... |
| CVE-2026-32202 | MEDIUM | 4.3 | 63.7% | Apr 14, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-32201 | MEDIUM | 6.5 | 24.2% | Apr 14, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a netw... |
| CVE-2026-32196 | MEDIUM | 6.1 | 0.3% | Apr 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u... |
| CVE-2026-32181 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. |
| CVE-2026-32151 | MEDIUM | 6.5 | 0.7% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in... |
| CVE-2026-32088 | MEDIUM | 5.7 | 0.2% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service... |
| CVE-2026-32085 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacke... |
| CVE-2026-32084 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-32081 | MEDIUM | 5.5 | 0.4% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
| CVE-2026-32079 | MEDIUM | 5.5 | 0.3% | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now