2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26197HIGH7.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor...
CVE-2026-25039HIGH8.8Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit...
CVE-2026-21824HIGH8.8HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso...
CVE-2026-63091HIGH7.1ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r...
CVE-2026-63090HIGH8.8ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo...
CVE-2026-62418HIGH8.1Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso...
CVE-2026-54910HIGH7.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ...
CVE-2026-52349HIGH7.8Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a...
CVE-2026-46410HIGH8.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le...
CVE-2026-45270HIGH8.7CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module...
CVE-2026-16252HIGH7.3A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ...
CVE-2026-16248HIGH8.8A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ...
CVE-2026-12080HIGH7.3A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a...
CVE-2026-64623HIGH8.8Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the...
CVE-2026-63763HIGH8.8SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg...
CVE-2026-63760HIGH8.7SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin...
CVE-2026-63759HIGH7.1SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot...
CVE-2026-63757HIGH8.8SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at...
CVE-2026-63755HIGH7.1SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i...
CVE-2026-63754HIGH7.1SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause...
CVE-2026-63750HIGH7.5SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c...
CVE-2026-63747HIGH8.7SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ...
CVE-2026-63746HIGH7.1SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references....
CVE-2026-63740HIGH7.1SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users...
CVE-2026-63739HIGH8.3SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now