2026 CVE Vulnerabilities
56,990 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49177 | MEDIUM | 5.5 | 0.3% | Jul 14, 2026 | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
| CVE-2026-48580 | MEDIUM | 5.5 | 0.5% | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-48368 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48365 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48309 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-47969 | MEDIUM | 5.5 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attack... |
| CVE-2026-47968 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-47967 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-47642 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-47295 | HIGH | 8.8 | 0.9% | Jul 14, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ... |
| CVE-2026-47290 | HIGH | 7.8 | 0.4% | Jul 14, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-45756 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until... |
| CVE-2026-45077 | HIGH | 8.6 | 0.6% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45074 | HIGH | 8.1 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.1... |
| CVE-2026-45067 | MEDIUM | 6.3 | — | Jul 14, 2026 | ### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply... |
| CVE-2026-45066 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until... |
| CVE-2026-45065 | MEDIUM | 6.1 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-15757 | MEDIUM | 6.3 | 0.2% | Jul 14, 2026 | A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send... |
| CVE-2026-15747 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH... |
| CVE-2026-15715 | MEDIUM | 4.3 | — | Jul 14, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i... |
| CVE-2026-0515 | MEDIUM | 6.2 | 0.1% | Jul 14, 2026 | Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra... |
| CVE-2026-59891 | CRITICAL | 9.6 | 0.3% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials... |
| CVE-2026-59888 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-59886 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon... |
| CVE-2026-59885 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now