2026 CVE Vulnerabilities

53,074 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26151HIGH7.1Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spo...
CVE-2026-26143HIGH7.8Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-25184HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (...
CVE-2026-23666HIGH7.5Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-23657HIGH7.8Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-20930HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic...
CVE-2026-0207HIGH8.5A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
CVE-2026-34622HIGH8.6Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo...
CVE-2026-27291HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-27284HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr...
CVE-2026-27283HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a...
CVE-2026-27238HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...
CVE-2026-39815HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD...
CVE-2026-38532HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2...
CVE-2026-38530HIGH8.1A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2....
CVE-2026-38529HIGH8.8A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo...
CVE-2026-38528HIGH7.1Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDat...
CVE-2026-38527HIGH8.5A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac...
CVE-2026-23708HIGH8.1A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5...
CVE-2026-22828HIGH8.1A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2...
CVE-2026-22155HIGH7.5A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA...
CVE-2026-4369HIGH7.1A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and...
CVE-2026-4345HIGH7.1A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripti...
CVE-2026-4344HIGH7.1A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked...
CVE-2026-2450HIGH7.4.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now