2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8959CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire...
CVE-2026-8958HIGH8.6Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi...
CVE-2026-8957HIGH8.8Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140....
CVE-2026-8956CRITICAL9.8Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thun...
CVE-2026-8955HIGH8.8Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu...
CVE-2026-8954HIGH7.5Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 15...
CVE-2026-8953CRITICAL9.6Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-8952HIGH8.8Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15...
CVE-2026-8951MEDIUM6.5Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-8950CRITICAL9.3Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14...
CVE-2026-8949HIGH7.5Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde...
CVE-2026-8948CRITICAL9.1Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ...
CVE-2026-8947HIGH7.3Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,...
CVE-2026-8946HIGH7.5Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir...
CVE-2026-8945HIGH7.5Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-6354——Rejected reason: Voluntarily withdrawn
CVE-2026-47323CRITICAL9.8Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra...
CVE-2026-43633CRITICAL10HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ...
CVE-2026-42100HIGH7.5Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ...
CVE-2026-42099HIGH7.5Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica...
CVE-2026-42098HIGH8.7Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An...
CVE-2026-42097HIGH8.8Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ...
CVE-2026-42096HIGH8.8Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per...
CVE-2026-23558HIGH7.8The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ...
CVE-2026-23557MEDIUM6.5Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now