2026 CVE Vulnerabilities

60,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49260HIGH8.2PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/...
CVE-2026-3196MEDIUM5.5An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious g...
CVE-2026-3195HIGH7.4A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f...
CVE-2026-12622MEDIUM5.4The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issu...
CVE-2026-12621MEDIUM5.4Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form...
CVE-2026-12620MEDIUM6.5The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G...
CVE-2026-12619MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G...
CVE-2026-52910HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio...
CVE-2026-52909HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device...
CVE-2026-52908HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c...
CVE-2026-49358LOW3PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene...
CVE-2026-21768MEDIUM6.3The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope...
CVE-2026-9143MEDIUM5.3There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co...
CVE-2026-9142CRITICAL9.3There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s...
CVE-2026-4027HIGH7.1A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces...
CVE-2026-4026HIGH8.7A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit...
CVE-2026-49872HIGH8.1Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po...
CVE-2026-49871CRITICAL9.3Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows...
CVE-2026-49357HIGH8.8Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o...
CVE-2026-49231MEDIUM5.4Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst...
CVE-2026-49230CRITICAL9.1Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi...
CVE-2026-48895HIGH7.2URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ...
CVE-2026-48141HIGH7.5There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti...
CVE-2026-48140HIGH7.1There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge...
CVE-2026-48139HIGH8.7There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now