2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64832 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc... |
| CVE-2026-16157 | HIGH | 7.8 | 0.1% | Jul 22, 2026 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In... |
| CVE-2026-65013 | HIGH | 8.8 | 0.5% | Jul 22, 2026 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a... |
| CVE-2026-64831 | HIGH | 8.8 | 0.5% | Jul 22, 2026 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder tha... |
| CVE-2026-64830 | HIGH | 8.8 | 0.4% | Jul 22, 2026 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo... |
| CVE-2026-49499 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera... |
| CVE-2026-46738 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-46737 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-40714 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig... |
| CVE-2026-40712 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-16607 | HIGH | 8.5 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-48029 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image... |
| CVE-2026-14985 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the ... |
| CVE-2026-13321 | HIGH | 8.6 | — | Jul 22, 2026 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon... |
| CVE-2026-13204 | HIGH | 7.5 | — | Jul 22, 2026 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on... |
| CVE-2026-12617 | HIGH | 7.5 | — | Jul 22, 2026 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME ... |
| CVE-2026-11721 | HIGH | 7.5 | — | Jul 22, 2026 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z... |
| CVE-2026-11622 | HIGH | 7.5 | — | Jul 22, 2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa... |
| CVE-2026-11605 | HIGH | 7.5 | — | Jul 22, 2026 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco... |
| CVE-2026-11331 | HIGH | 7.5 | — | Jul 22, 2026 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou... |
| CVE-2026-62145 | HIGH | 7.5 | 0.4% | Jul 22, 2026 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe... |
| CVE-2026-55973 | HIGH | 7.5 | 0.3% | Jul 22, 2026 | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel... |
| CVE-2026-44690 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with ... |
| CVE-2026-40691 | HIGH | 7.5 | 0.3% | Jul 22, 2026 | In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r... |
| CVE-2026-32665 | HIGH | 7.5 | 0.3% | Jul 22, 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now