2026 CVE Vulnerabilities

60,364 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47774HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7...
CVE-2026-3894CRITICAL9.1Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects...
CVE-2026-39199LOW2.9snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-30803CRITICAL9.1Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This ...
CVE-2026-30802HIGH8.2Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connex...
CVE-2026-30799HIGH8.1Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identit...
CVE-2026-2675MEDIUM6.5Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th...
CVE-2026-2674HIGH8.1Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servic...
CVE-2026-2467HIGH8.1Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags...
CVE-2026-20266CRITICAL9.1In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands ...
CVE-2026-20265MEDIUM4.3In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles ...
CVE-2026-20178MEDIUM4.3A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker t...
CVE-2026-11525LOW3.7Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No...
CVE-2026-9675HIGH7.5Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme...
CVE-2026-53875HIGH7.1picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to e...
CVE-2026-53874CRITICAL9.8picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbit...
CVE-2026-53873CRITICAL9.8picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level pro...
CVE-2026-53872HIGH8.7picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to r...
CVE-2026-3490CRITICAL10picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolv...
CVE-2026-36418CRITICAL9.1JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi...
CVE-2026-35069HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2026-35068MEDIUM5.7Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2026-32652HIGH7.8Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged att...
CVE-2026-20246MEDIUM6A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e...
CVE-2026-20220MEDIUM6.3A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now