2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-61544HIGH8.2libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic co...
CVE-2026-51134HIGH7.5The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' paramete...
CVE-2026-18424HIGH7.1Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a h...
CVE-2026-18423HIGH7.1Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search p...
CVE-2026-13327HIGH8.3Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier all...
CVE-2026-92180HIGH7.8pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vul...
CVE-2026-92179HIGH7.8pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2026-92178HIGH7.8pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2026-92177HIGH7.8pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2026-92176HIGH7.8pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo...
CVE-2026-82189HIGH8.7Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0...
CVE-2026-81568HIGH8.7Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-...
CVE-2026-81567HIGH8.7Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-...
CVE-2026-79411HIGH8.8Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated ba...
CVE-2026-79410HIGH8.1Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated atta...
CVE-2026-78081HIGH7.1Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0...
CVE-2026-69213HIGH7.5Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames t...
CVE-2026-69209HIGH7.5Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbo...
CVE-2026-69208HIGH7.5Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes ...
CVE-2026-58766HIGH7.8In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th...
CVE-2026-58744HIGH7.8In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to ...
CVE-2026-58734HIGH7In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could...
CVE-2026-58728HIGH7In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalati...
CVE-2026-58724HIGH7In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation o...
CVE-2026-58710HIGH8.8In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. Th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now