2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-64832HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc...
CVE-2026-16157HIGH7.8Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In...
CVE-2026-65013HIGH8.8Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a...
CVE-2026-64831HIGH8.8FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder tha...
CVE-2026-64830HIGH8.8FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo...
CVE-2026-49499HIGH8.8Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera...
CVE-2026-46738HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-46737HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-40714HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig...
CVE-2026-40712HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-16607HIGH8.5A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow...
CVE-2026-48029HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image...
CVE-2026-14985HIGH7.8The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the ...
CVE-2026-13321HIGH8.6The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon...
CVE-2026-13204HIGH7.5If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on...
CVE-2026-12617HIGH7.5The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME ...
CVE-2026-11721HIGH7.5It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z...
CVE-2026-11622HIGH7.5A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa...
CVE-2026-11605HIGH7.5The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco...
CVE-2026-11331HIGH7.5An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou...
CVE-2026-62145HIGH7.5A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe...
CVE-2026-55973HIGH7.5In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel...
CVE-2026-44690HIGH7.5In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with ...
CVE-2026-40691HIGH7.5In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r...
CVE-2026-32665HIGH7.5In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now