2026 CVE Vulnerabilities

44,805 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-16331HIGH7.3A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/fu...
CVE-2026-16330HIGH7.3A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jqu...
CVE-2026-16329HIGH7.3A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/up...
CVE-2026-63728HIGH8.1Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence r...
CVE-2026-55833HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-55831HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-16327HIGH7.3A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_...
CVE-2026-15905HIGH7.8Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap cor...
CVE-2026-15904HIGH8.8Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user...
CVE-2026-15903HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitra...
CVE-2026-15902HIGH8.8Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-64624HIGH8.5FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e...
CVE-2026-57495HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, ...
CVE-2026-57494HIGH7.1AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p...
CVE-2026-55550HIGH7.1NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide ...
CVE-2026-55544HIGH7.6NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose...
CVE-2026-51031HIGH7.5FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T...
CVE-2026-47255HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti...
CVE-2026-16324HIGH7.3A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function ...
CVE-2026-56624HIGH7.3Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side an...
CVE-2026-56623HIGH7.1Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and...
CVE-2026-56452HIGH7.5Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser...
CVE-2026-47198HIGH8.5Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the...
CVE-2026-47130HIGH7.1NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le...
CVE-2026-47129HIGH8.1NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now