2026 CVE Vulnerabilities

44,991 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54340HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am...
CVE-2026-39359HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ...
CVE-2026-34150HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov...
CVE-2026-33434HIGH7.1Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov...
CVE-2026-44453HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni...
CVE-2026-44436HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...
CVE-2026-44435HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93...
CVE-2026-44433HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...
CVE-2026-43978HIGH8.1wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess...
CVE-2026-43977HIGH7.5wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth...
CVE-2026-59117HIGH7.5Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
CVE-2026-58598HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-57077HIGH7.7YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t...
CVE-2026-57076HIGH7.8YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i...
CVE-2026-53411HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...
CVE-2026-45368HIGH8.4Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for ...
CVE-2026-44177HIGH8.8Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct...
CVE-2026-44175HIGH8.5Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize...
CVE-2026-44174HIGH8.7Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes...
CVE-2026-55173HIGH8.1WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because ...
CVE-2026-53410HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...
CVE-2026-53409HIGH7.8Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct ...
CVE-2026-44023HIGH8.6Docling Core defines core data types and transformations for the document processing application Docling. In versions 1....
CVE-2026-44019HIGH8.1Docling Core defines core data types and transformations for the document processing application Docling. In versions 2....
CVE-2026-33692HIGH7.5WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now