2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25571MEDIUM5.5A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe...
CVE-2026-25186MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows...
CVE-2026-25185MEDIUM5.3Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attac...
CVE-2026-25180MEDIUM5.5Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
CVE-2026-25169MEDIUM5.5Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
CVE-2026-25168MEDIUM5.5Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
CVE-2026-24641MEDIUM6.5A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6....
CVE-2026-24640MEDIUM6.6A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7...
CVE-2026-24297MEDIUM4.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows a...
CVE-2026-24288MEDIUM6.8Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical a...
CVE-2026-24282MEDIUM5.5Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
CVE-2026-23907MEDIUM5.3This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3....
CVE-2026-23656MEDIUM5.9Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof...
CVE-2026-22628MEDIUM6.7An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a...
CVE-2026-22614MEDIUM6.1The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a...
CVE-2026-1286MEDIUM6.5CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an...
CVE-2026-30927MEDIUM5.4Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event par...
CVE-2026-30919MEDIUM5.4facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as...
CVE-2026-30918MEDIUM6.1facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs wh...
CVE-2026-30913MEDIUM4.6Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni...
CVE-2026-30885MEDIUM5.3WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al...
CVE-2026-30870MEDIUM6.5PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre...
CVE-2026-29773MEDIUM4.3Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name...
CVE-2026-28512MEDIUM6.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo...
CVE-2026-28267MEDIUM6.8Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now