2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0119MEDIUM6.8In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This ...
CVE-2026-0108MEDIUM4The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure wi...
CVE-2026-3582MEDIUM4.3An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w...
CVE-2026-2266MEDIUM5.4An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cros...
CVE-2026-29177MEDIUM5.4Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vu...
CVE-2026-29176MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce...
CVE-2026-29175MEDIUM5.4Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce ...
CVE-2026-29173MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when...
CVE-2026-29113MEDIUM4.3Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token e...
CVE-2026-26311MEDIUM5.9Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerabili...
CVE-2026-26309MEDIUM5.3Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write...
CVE-2026-26123MEDIUM5.5Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
CVE-2026-23868MEDIUM5.1Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro...
CVE-2026-27281MEDIUM5.5DNG SDK versions 1.7.1 2471 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead ...
CVE-2026-27219MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-27218MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27217MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27216MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-27215MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27214MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-21365MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-21364MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-21363MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-3862MEDIUM4.8Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unal...
CVE-2026-3846MEDIUM6.5Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now