CVEs from 2026

14,112 normalized CVEs published or assigned in this year.

Total
14,112
critical
critical 1,245
high
high 4,691
medium
medium 4,468
low
low 488
% Critical
8.8%
% with KEV
0.4%
% with exploit
0.8%

Top vendors

Top products

  • chrome 522
  • firepower_threat_defense_software 300
  • firepower_threat_defense 298
  • gcp 247
  • openclaw 172
  • commerce 104
  • netweaver_application_server_abap 102
  • commerce_b2b 89
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44376 medium 6.1 7.1 21d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p…
CVE-2026-6815 medium 5.9 6.9 23d ago An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perfo…
CVE-2026-32202 medium 4.3 6.8 2mo ago Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-44596 medium 6.5 8d ago Yamcs has No Rate Limiting on Authentication Endpoint
CVE-2026-44595 medium 6.5 8d ago Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
CVE-2026-42568 medium 6.5 8d ago Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-33829 medium 4.3 5.3 2mo ago Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.