2026 CVE Vulnerabilities

44,115 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-16396HIGH8.8Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,...
CVE-2026-16391HIGH7.5Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140...
CVE-2026-16386HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16385HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16384HIGH7.5Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi...
CVE-2026-16379HIGH8.8Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 1...
CVE-2026-16378HIGH7.5Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderb...
CVE-2026-16376HIGH7.5Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16374HIGH7.5Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR ...
CVE-2026-16373HIGH7.5Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16372HIGH8.8Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbir...
CVE-2026-16371HIGH8.8Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, ...
CVE-2026-16366HIGH8.8Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16365HIGH8.8Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16362HIGH8.8Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Th...
CVE-2026-16354HIGH7.5Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-60080HIGH7.3Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13....
CVE-2026-1771HIGH7.2The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi...
CVE-2026-15370HIGH7.3A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten...
CVE-2026-3183HIGH7.1Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
CVE-2026-8082HIGH7.5The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQ...
CVE-2026-11767HIGH8.8The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef...
CVE-2026-59776HIGH7Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v...
CVE-2026-6952HIGH7.2A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B...
CVE-2026-16332HIGH7.3A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now