2026 CVE Vulnerabilities

56,990 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49177MEDIUM5.5Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
CVE-2026-48580MEDIUM5.5Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-48368HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48365HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48309HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47969MEDIUM5.5Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attack...
CVE-2026-47968HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47967HIGH7.8Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-47642HIGH7.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-47295HIGH8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized ...
CVE-2026-47290HIGH7.8Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45756HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until...
CVE-2026-45077HIGH8.6Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45074HIGH8.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.1...
CVE-2026-45067MEDIUM6.3### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply...
CVE-2026-45066MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45065MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-15757MEDIUM6.3A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send...
CVE-2026-15747CRITICAL9.1Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH...
CVE-2026-15715MEDIUM4.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-0515MEDIUM6.2Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra...
CVE-2026-59891CRITICAL9.6sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials...
CVE-2026-59888MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-59886HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon...
CVE-2026-59885HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now