2026 CVE Vulnerabilities

61,030 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56211HIGH7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v...
CVE-2026-56210HIGH7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds ...
CVE-2026-56209HIGH7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c...
CVE-2026-56208HIGH7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco...
CVE-2026-51846CRITICAL9.8In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulne...
CVE-2026-51845CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the m...
CVE-2026-51844CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the c...
CVE-2026-51843CRITICAL9.8Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w...
CVE-2026-49260HIGH8.2PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/...
CVE-2026-3196MEDIUM5.5An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious g...
CVE-2026-3195HIGH7.4A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f...
CVE-2026-12622MEDIUM5.4The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issu...
CVE-2026-12621MEDIUM5.4Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form...
CVE-2026-12620MEDIUM6.5The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G...
CVE-2026-12619MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G...
CVE-2026-52910HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio...
CVE-2026-52909HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device...
CVE-2026-52908HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c...
CVE-2026-49358LOW3PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene...
CVE-2026-21768MEDIUM6.3The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope...
CVE-2026-9143MEDIUM5.3There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co...
CVE-2026-9142CRITICAL9.3There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s...
CVE-2026-4027HIGH7.1A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces...
CVE-2026-4026HIGH8.7A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit...
CVE-2026-49872HIGH8.1Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now