2026 CVE Vulnerabilities

46,870 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...
CVE-2026-11814MEDIUM4.9A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in...
CVE-2026-11739MEDIUM4.9A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with...
CVE-2026-11738MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-11737MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ...
CVE-2026-11736LOW1.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ...
CVE-2026-11735LOW1.9A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma...
CVE-2026-11734LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...
CVE-2026-11733LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ...
CVE-2026-73067MEDIUM6.7Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca...
CVE-2026-73066MEDIUM6.8Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse...
CVE-2026-72925MEDIUM6.1SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi...
CVE-2026-72922HIGH8.2AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-72921HIGH8.1SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth...
CVE-2026-72920CRITICAL9.8SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s...
CVE-2026-47702CRITICAL9.1TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu...
CVE-2026-18860HIGH8.7Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr...
CVE-2026-18636MEDIUM6.8The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr...
CVE-2026-18635HIGH7.2Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ...
CVE-2026-18129HIGH8.1Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ...
CVE-2026-18127HIGH7.7External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica...
CVE-2026-18125HIGH7.5An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at...
CVE-2026-17535MEDIUM6.2Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by...
CVE-2026-17061CRITICAL10A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now