2026 CVE Vulnerabilities

55,483 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23668HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2026-23667HIGH7Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
CVE-2026-23665HIGH7.8Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.
CVE-2026-23664HIGH7.5Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke...
CVE-2026-23662HIGH7.5Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati...
CVE-2026-23661HIGH7.5Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose inform...
CVE-2026-23660HIGH7.8Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally...
CVE-2026-23654HIGH8.8Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to...
CVE-2026-23239HIGH7.8In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() T...
CVE-2026-22627HIGH8.8A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1....
CVE-2026-22572HIGH7.2An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,...
CVE-2026-21262HIGH8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20967HIGH8.8Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a...
CVE-2026-1261HIGH7.2The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions u...
CVE-2026-3585HIGH7.5The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15....
CVE-2026-30925HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a...
CVE-2026-30920HIGH8.6OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t...
CVE-2026-30917HIGH8.8Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be i...
CVE-2026-2364HIGH7.3If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr...
CVE-2026-28513HIGH7.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th...
CVE-2026-28281HIGH7.1InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token...
CVE-2026-27689HIGH7.7Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us...
CVE-2026-30931HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30929HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30926HIGH7.1SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now