2026 CVE Vulnerabilities

60,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48089HIGH7.1DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc...
CVE-2026-9375Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49340HIGH8.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e...
CVE-2026-49339HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6...
CVE-2026-49338HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso...
CVE-2026-49336MEDIUM5.5@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev...
CVE-2026-49293HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa...
CVE-2026-49291HIGH8.1mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo...
CVE-2026-49288MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con...
CVE-2026-27878MEDIUM6.5A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive...
CVE-2026-12726MEDIUM6.3A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto...
CVE-2026-12238MEDIUM5.3The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t...
CVE-2026-49359MEDIUM6.5PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...
CVE-2026-49290HIGH7.6Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr...
CVE-2026-49287HIGH7.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026...
CVE-2026-49286HIGH8.1PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...
CVE-2026-49271MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid...
CVE-2026-56211HIGH7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v...
CVE-2026-56210HIGH7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds ...
CVE-2026-56209HIGH7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c...
CVE-2026-56208HIGH7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco...
CVE-2026-51846CRITICAL9.8In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulne...
CVE-2026-51845CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the m...
CVE-2026-51844CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the c...
CVE-2026-51843CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now