2026 CVE Vulnerabilities

57,147 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54260LOW2.7Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an aut...
CVE-2026-54259MEDIUM4.3Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do...
CVE-2026-52190HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52186CRITICAL9.8SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod...
CVE-2026-38891HIGH7.5An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau...
CVE-2026-36912HIGH7.5A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3...
CVE-2026-36911MEDIUM5.5A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE befor...
CVE-2026-36910MEDIUM5.5An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers...
CVE-2026-36909MEDIUM6.2A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow...
CVE-2026-58263HIGH7.2Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in...
CVE-2026-55886MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to ...
CVE-2026-55661MEDIUM4.8Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text par...
CVE-2026-55660HIGH7.6Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po...
CVE-2026-55153HIGH7.1mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool....
CVE-2026-54786MEDIUM5Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver...
CVE-2026-54756MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior ...
CVE-2026-54720MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med...
CVE-2026-54074HIGH7.8Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne...
CVE-2026-50521HIGH8.3Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-14340MEDIUM5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token ...
CVE-2026-58593HIGH8.7NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound ...
CVE-2026-58592HIGH8.3Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration modul...
CVE-2026-58457CRITICAL9.8Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability...
CVE-2026-55688MEDIUM4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-54908MEDIUM6.3Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now