2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19556HIGH8.8Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-18710HIGH8.2A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net...
CVE-2026-71290CRITICAL9.1Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic...
CVE-2026-66832MEDIUM6.9When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app...
CVE-2026-66154HIGH8.3An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1...
CVE-2026-66150HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66149HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66148MEDIUM6.3An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10...
CVE-2026-66147CRITICAL9.4An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier...
CVE-2026-63177HIGH7.1Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng...
CVE-2026-63134MEDIUM5.4Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w...
CVE-2026-63133MEDIUM6.5Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives...
CVE-2026-55676HIGH8.8Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P...
CVE-2026-48765CRITICAL9.9TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa...
CVE-2026-48763HIGH8.2TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t...
CVE-2026-48762MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u...
CVE-2026-29035HIGH8.3CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that...
CVE-2026-19579MEDIUM5.4Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ...
CVE-2026-19550MEDIUM4.3A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath...
CVE-2026-18634HIGH8.4An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B...
CVE-2026-15606HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-14863HIGH8.8FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at...
CVE-2026-73283LOW2.5In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar...
CVE-2026-73282MEDIUM4.8In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat...
CVE-2026-73281LOW3.5In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now