2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65705HIGH7.8FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that all...
CVE-2026-65704HIGH7.8FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by sup...
CVE-2026-65703HIGH8.5FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows rem...
CVE-2026-60122HIGH8.5gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha...
CVE-2026-47722HIGH8.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `inter...
CVE-2026-25800HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and...
CVE-2026-15212HIGH8.8The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43...
CVE-2026-63765HIGH8.8Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau...
CVE-2026-16756HIGH8.7Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o...
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-47743HIGH8.7Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed...
CVE-2026-65759HIGH8.7Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical...
CVE-2026-65695HIGH7.6Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker...
CVE-2026-44909HIGH7.5Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate...
CVE-2026-65917HIGH8.8CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ...
CVE-2026-65916HIGH8.1CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre...
CVE-2026-16584HIGH7.3Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to ...
CVE-2026-15615HIGH7.5Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and ...
CVE-2026-15614HIGH7.5Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid...
CVE-2026-43823HIGH7.5When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c...
CVE-2026-43820HIGH7.7NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to...
CVE-2026-65898HIGH7.2DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute...
CVE-2026-65690HIGH8.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now