2026 CVE Vulnerabilities

46,868 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-73074HIGH7.1Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen va...
CVE-2026-73072HIGH8.5Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] ...
CVE-2026-73071LOW3.3Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta...
CVE-2026-73070MEDIUM6.8Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c acce...
CVE-2026-73069CRITICAL9.1Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad...
CVE-2026-73068MEDIUM5.9ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-6727MEDIUM5.9A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a...
CVE-2026-6726HIGH7.9An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi...
CVE-2026-67180HIGH8.4Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing ...
CVE-2026-67179HIGH7.8Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop...
CVE-2026-56721HIGH8.8CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference...
CVE-2026-56720MEDIUM5.3CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ...
CVE-2026-53416HIGH7.1Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca...
CVE-2026-53415HIGH8.3Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code executio...
CVE-2026-53414MEDIUM6.5Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic...
CVE-2026-53413HIGH8.3Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting parti...
CVE-2026-48766HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr...
CVE-2026-48495HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS...
CVE-2026-42142HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee...
CVE-2026-19546HIGH8.8A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S...
CVE-2026-19078MEDIUM4.3A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the...
CVE-2026-18640HIGH7.1The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm...
CVE-2026-18639HIGH7.3When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s...
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now