2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-63047HIGH7.5Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - ...
CVE-2026-3821HIGH8.8Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attack...
CVE-2026-12987HIGH7.5The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-Use...
CVE-2026-12968HIGH8.8The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent...
CVE-2026-15802HIGH8.1The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...
CVE-2026-56844HIGH8.4A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate ...
CVE-2026-56819HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug...
CVE-2026-16423HIGH8.8Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage i...
CVE-2026-16422HIGH7.5Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a...
CVE-2026-16421HIGH8.8Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute a...
CVE-2026-16420HIGH8.8Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code ...
CVE-2026-16418HIGH8.8Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code...
CVE-2026-16414HIGH7.8Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack...
CVE-2026-16413HIGH8.3Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ...
CVE-2026-8987HIGH8.8Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command ha...
CVE-2026-65319HIGH8.7Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated at...
CVE-2026-65316HIGH7.1XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read...
CVE-2026-65315HIGH8.7Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows r...
CVE-2026-62574HIGH7.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-62567HIGH7.7Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th...
CVE-2026-62565HIGH7.1Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported ve...
CVE-2026-62561HIGH7.8Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve...
CVE-2026-62560HIGH7.7Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supporte...
CVE-2026-62557HIGH7.1Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th...
CVE-2026-62548HIGH7.2Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now