2026 CVE Vulnerabilities

61,264 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-36933MEDIUM6.8An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi...
CVE-2026-36670HIGH8.8A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr...
CVE-2026-36537CRITICAL9.8ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The applica...
CVE-2026-36521MEDIUM6.1PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
CVE-2026-36213HIGH7.8An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e...
CVE-2026-30121CRITICAL9.1remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
CVE-2026-30120CRITICAL9.8remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2026-11931MEDIUM6.8Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok...
CVE-2026-8358MEDIUM5.4LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ...
CVE-2026-8357HIGH7.8LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very...
CVE-2026-8356MEDIUM5.4LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c...
CVE-2026-6047MEDIUM5.4LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars...
CVE-2026-6045MEDIUM5.4LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ...
CVE-2026-6040HIGH7.3A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f...
CVE-2026-6039MEDIUM5.4LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ...
CVE-2026-49294MEDIUM6.1Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and...
CVE-2026-47777HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ...
CVE-2026-20262MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-9863HIGH8.8Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta...
CVE-2026-9862CRITICAL9.8Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd...
CVE-2026-9595MEDIUM4.3Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts...
CVE-2026-8683MEDIUM6.5Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm...
CVE-2026-5038HIGH7.5Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d...
CVE-2026-10634MEDIUM5.3Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S...
CVE-2026-6517HIGH7.7Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now