2026 CVE Vulnerabilities

55,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56167HIGH8.8Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network...
CVE-2026-56165CRITICAL9.8Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56160CRITICAL9.9Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-54120HIGH8.8Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-50517CRITICAL9.9Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-49159MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ...
CVE-2026-35425HIGH7.2Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-50044HIGH7.6Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an...
CVE-2026-44955MEDIUM6.9Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-42933CRITICAL10Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow ...
CVE-2026-40430HIGH8.7Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl...
CVE-2026-28698CRITICAL9.2Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr...
CVE-2026-16767MEDIUM6.5A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr...
CVE-2026-65694HIGH8.7Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthen...
CVE-2026-65604HIGH8.8Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) d...
CVE-2026-63732CRITICAL9.99router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authent...
CVE-2026-63313HIGH8.39Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The end...
CVE-2026-16807HIGH8.8Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform ...
CVE-2026-16806HIGH8.8Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code in...
CVE-2026-16805HIGH8.8Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-16804HIGH8.3Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the rende...
CVE-2026-16765HIGH7.3A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality o...
CVE-2026-16764MEDIUM6.3A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file do...
CVE-2026-16763MEDIUM5.3A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct...
CVE-2026-6924HIGH8.7A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers g...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now