2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30117CRITICAL9.8scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame...
CVE-2026-8711CRITICAL9.8NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled...
CVE-2026-47100HIGH8.7Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public c...
CVE-2026-45557MEDIUM6.9Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con...
CVE-2026-44159CRITICAL9.8Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c...
CVE-2026-43634HIGH8.7HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers ...
CVE-2026-34883MEDIUM5.3An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a ...
CVE-2026-2587CRITICAL9.6A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used...
CVE-2026-2586CRITICAL9.1An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ...
CVE-2026-8975HIGH8.8Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence...
CVE-2026-8974HIGH8.8Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruptio...
CVE-2026-8973HIGH8.8Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2026-8972HIGH8.8Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 1...
CVE-2026-8971MEDIUM6.5Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-8970HIGH8.8Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunder...
CVE-2026-8969HIGH8.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8968HIGH7.5Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef...
CVE-2026-8967HIGH7.5Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 15...
CVE-2026-8966HIGH7.5Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8965HIGH7.5Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8964HIGH7.5Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8963HIGH7.5Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8962HIGH8.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thund...
CVE-2026-8961MEDIUM6.5Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb...
CVE-2026-8960HIGH7.5Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now