2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-15792HIGH7.5A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
CVE-2026-15791HIGH7.5A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti...
CVE-2026-15789HIGH7.5A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro...
CVE-2026-15724HIGH8.7In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user ...
CVE-2026-15432HIGH8.2When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar...
CVE-2026-47394HIGH8.7PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in...
CVE-2026-8933HIGH7.8A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by ...
CVE-2026-65052HIGH8.7Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un...
CVE-2026-65050HIGH7.1Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb...
CVE-2026-59851HIGH8.8A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the...
CVE-2026-59850HIGH7.5A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok...
CVE-2026-59849HIGH7.5A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien...
CVE-2026-46681HIGH7.2@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps fu...
CVE-2026-15226HIGH8.4A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler ...
CVE-2026-59847HIGH7.5A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re...
CVE-2026-16447HIGH7.3A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader...
CVE-2026-16445HIGH7.5A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia...
CVE-2026-16409HIGH7.5Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16405HIGH7.5Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR...
CVE-2026-16404HIGH7.4Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16401HIGH8.8Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird ...
CVE-2026-16400HIGH7.5Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16399HIGH7.5Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16398HIGH7.5Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16396HIGH8.8Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now