2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15714MEDIUM6.5An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m...
CVE-2026-15713MEDIUM5.9A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con...
CVE-2026-15711HIGH7.5A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule...
CVE-2026-15709HIGH7.5A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco...
CVE-2026-15410HIGH7.2Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S...
CVE-2026-15409CRITICAL10A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A ...
CVE-2026-13001CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2026-5040MEDIUM6.7TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo...
CVE-2026-47767CRITICAL9.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4....
CVE-2026-47305HIGH7.8Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-47304CRITICAL9.8Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov...
CVE-2026-47303HIGH8.8Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over...
CVE-2026-47302HIGH7.5Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
CVE-2026-47301HIGH8.8Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a ne...
CVE-2026-47300HIGH8.8Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges...
CVE-2026-45755MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8....
CVE-2026-45754MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45753MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45305HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45304HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45133HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45075HIGH8.2Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8....
CVE-2026-45073HIGH7.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45072MEDIUM5.4Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4....
CVE-2026-45070MEDIUM6.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now