2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30041HIGH7.5An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code...
CVE-2026-30040MEDIUM6.5A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary...
CVE-2026-24547MEDIUM5.3Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
CVE-2026-57940LOW2.1HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi...
CVE-2026-57926CRITICAL9.8In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
CVE-2026-57925MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
CVE-2026-57924MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
CVE-2026-57923HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr...
CVE-2026-57922MEDIUM5.3In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-57921HIGH7.5In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te...
CVE-2026-53914CRITICAL9.8In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
CVE-2026-13426MEDIUM5.4The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet...
CVE-2026-57920HIGH7.7Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai...
CVE-2026-57915HIGH7.3It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized...
CVE-2026-40711HIGH8Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po...
CVE-2026-57914MEDIUM6.5By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow ...
CVE-2026-57620MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu...
CVE-2026-57918HIGH7.1libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d...
CVE-2026-57913HIGH7.5Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc...
CVE-2026-57912HIGH7.5Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e...
CVE-2026-57473MEDIUM5.8A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)...
CVE-2026-13325Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2026-6658MEDIUM5.4A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd....
CVE-2026-1869MEDIUM6.5The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-11702HIGH7.5Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now