2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70638HIGH8.5llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th...
CVE-2026-70636HIGH8.7Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th...
CVE-2026-70635HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica...
CVE-2026-70634HIGH8.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers...
CVE-2026-70633HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres...
CVE-2026-70632HIGH8.5FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G...
CVE-2026-70631MEDIUM6.8FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in ...
CVE-2026-70630MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-70629MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-70628HIGH8.5FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit...
CVE-2026-70559HIGH8.7Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t...
CVE-2026-70558CRITICAL9.8Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) ...
CVE-2026-70557HIGH7.1diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of ...
CVE-2026-69125Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a ...
CVE-2026-69124Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a ...
CVE-2026-69123Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason: This candidate is a ...
CVE-2026-68948Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a ...
CVE-2026-68947Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason: This candidate is a ...
CVE-2026-68946Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason: This candidate is a ...
CVE-2026-68944Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a ...
CVE-2026-68943Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a ...
CVE-2026-68942Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a ...
CVE-2026-68941Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a ...
CVE-2026-68480In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt in...
CVE-2026-67689CRITICAL9.8SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now