2026 CVE Vulnerabilities

50,391 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23670MEDIUM5.7Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by...
CVE-2026-23653MEDIUM6.5Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio ...
CVE-2026-21331MEDIUM6.1Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. I...
CVE-2026-20945MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-20928MEDIUM4.6Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una...
CVE-2026-20806MEDIUM5.5Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose i...
CVE-2026-0390MEDIUM6.7Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec...
CVE-2026-0209MEDIUM6.9Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than c...
CVE-2026-34626MEDIUM6.3Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo...
CVE-2026-27286MEDIUM5.5InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-27285MEDIUM5.5InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-22692MEDIUM6.8October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4...
CVE-2026-5713MEDIUM5.3The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" a...
CVE-2026-4832MEDIUM6.9CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device info...
CVE-2026-39814MEDIUM6.7A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb...
CVE-2026-39812MEDIUM4.8A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa...
CVE-2026-39811MEDIUM4.9A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, F...
CVE-2026-39810MEDIUM5.5A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to...
CVE-2026-39809MEDIUM6.7A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl...
CVE-2026-38533MEDIUM6.5An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attac...
CVE-2026-2405MEDIUM6.5CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creat...
CVE-2026-2404MEDIUM5.3CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when ...
CVE-2026-2403MEDIUM4.3CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log tru...
CVE-2026-2402MEDIUM5.3CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to g...
CVE-2026-2401MEDIUM5CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now