2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56167HIGH8.8Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network...
CVE-2026-54120HIGH8.8Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-35425HIGH8Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-50044HIGH7.6Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an...
CVE-2026-40430HIGH8.7Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl...
CVE-2026-65694HIGH8.7Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthen...
CVE-2026-65604HIGH8.8Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) d...
CVE-2026-63313HIGH8.39Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The end...
CVE-2026-16807HIGH8.8Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform ...
CVE-2026-16806HIGH8.8Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code in...
CVE-2026-16805HIGH8.8Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-16804HIGH8.3Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the rende...
CVE-2026-16765HIGH7.3A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality o...
CVE-2026-6924HIGH8.7A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers g...
CVE-2026-50103HIGH7.1A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to cra...
CVE-2026-50039HIGH8.7The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corru...
CVE-2026-50032HIGH8.7A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to ...
CVE-2026-47723HIGH7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none o...
CVE-2026-38764HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne...
CVE-2026-34496HIGH7.1Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before...
CVE-2026-21655HIGH8.7Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and J...
CVE-2026-21653HIGH7.2Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forger...
CVE-2026-16796HIGH8.4Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo...
CVE-2026-16002HIGH8.8The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process an...
CVE-2026-65706HIGH8.5FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now