2026 CVE Vulnerabilities

61,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45358MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45031MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-44692HIGH7.7Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic...
CVE-2026-42542HIGH7.5TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3...
CVE-2026-42462HIGH7Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10...
CVE-2026-42326MEDIUM5.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-2049HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-11604MEDIUM6.5An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allo...
CVE-2026-10143HIGH7.5kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma...
CVE-2026-10142HIGH8.7kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br...
CVE-2026-0274CRITICAL9.1An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X...
CVE-2026-0273HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2026-0272HIGH7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a...
CVE-2026-0271HIGH7.8A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l...
CVE-2026-0270HIGH7.5A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti...
CVE-2026-0269MEDIUM5.7A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an a...
CVE-2026-0268MEDIUM4.4A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffi...
CVE-2026-0267MEDIUM5.5An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn...
CVE-2026-0266MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated admi...
CVE-2026-6893HIGH7.5A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia...
CVE-2026-50127MEDIUM5.9Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did...
CVE-2026-46683MEDIUM6.9Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0...
CVE-2026-46643HIGH7.5Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1...
CVE-2026-46529HIGH8.4Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co...
CVE-2026-45106MEDIUM4.6Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now