2026 CVE Vulnerabilities

56,994 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41087MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-40422MEDIUM5.5Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-40400HIGH8Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
CVE-2026-40378HIGH7.5Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau...
CVE-2026-36214MEDIUM6.4osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable...
CVE-2026-34349MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in...
CVE-2026-34348MEDIUM6.5Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over...
CVE-2026-34346MEDIUM5.5Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at...
CVE-2026-34328MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis...
CVE-2026-33842MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis...
CVE-2026-15703HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn...
CVE-2026-15702MEDIUM6.3A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co...
CVE-2026-15701CRITICAL9.8A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo...
CVE-2026-15700MEDIUM4.7A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th...
CVE-2026-15429HIGH8.8A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling...
CVE-2026-15428HIGH8.8An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na...
CVE-2026-15427HIGH8.1An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf...
CVE-2026-14646MEDIUM4.9Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets re...
CVE-2026-14645MEDIUM5.1Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making ...
CVE-2026-9636HIGH8.2A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Secu...
CVE-2026-9292HIGH8.4A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability ste...
CVE-2026-9128HIGH7.5A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External...
CVE-2026-9127HIGH7.5A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con...
CVE-2026-9108HIGH7.5A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi...
CVE-2026-7494MEDIUM5.3Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now