2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22817MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i...
CVE-2026-22809MEDIUM4.4tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (R...
CVE-2026-21308MEDIUM5.5Substance3D - Designer versions 15.0.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t...
CVE-2026-22791MEDIUM6.1openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vul...
CVE-2026-21288MEDIUM5.5Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t...
CVE-2026-21278MEDIUM5.5InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t...
CVE-2026-21265MEDIUM6.4Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching ex...
CVE-2026-20962MEDIUM4.4Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose ...
CVE-2026-20959MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-20958MEDIUM5.4Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information ...
CVE-2026-20939MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-20937MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-20936MEDIUM4.3Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
CVE-2026-20935MEDIUM6.2Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to ...
CVE-2026-20932MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-20927MEDIUM5.3Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows...
CVE-2026-20925MEDIUM6.5External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network...
CVE-2026-20876MEDIUM6.7Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to eleva...
CVE-2026-20872MEDIUM6.5External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network...
CVE-2026-20862MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker ...
CVE-2026-20851MEDIUM6.2Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose informat...
CVE-2026-20847MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spo...
CVE-2026-20839MEDIUM5.5Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose informati...
CVE-2026-20838MEDIUM5.5Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose...
CVE-2026-20835MEDIUM5.5Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose informatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now