2026 CVE Vulnerabilities

52,241 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25184HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (...
CVE-2026-23666HIGH7.5Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-23657HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20930HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic...
CVE-2026-0207HIGH8.5A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
CVE-2026-34622HIGH8.6Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo...
CVE-2026-27291HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-27284HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr...
CVE-2026-27283HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a...
CVE-2026-27238HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-39815HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD...
CVE-2026-38532HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2...
CVE-2026-38530HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2....
CVE-2026-38529HIGH8.8A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo...
CVE-2026-38528HIGH7.1Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDat...
CVE-2026-38527HIGH8.5A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac...
CVE-2026-23708HIGH8.1A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5...
CVE-2026-22828HIGH8.1A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2...
CVE-2026-22155HIGH7.5A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA...
CVE-2026-4369HIGH7.1A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and...
CVE-2026-4345HIGH7.1A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripti...
CVE-2026-4344HIGH7.1A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked...
CVE-2026-2450HIGH7.4.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows...
CVE-2026-33892HIGH7.1A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial...
CVE-2026-31923HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now