2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66878HIGH7.7A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable...
CVE-2026-6484HIGH8.2In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CVE-2026-73249HIGH7.5calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar...
CVE-2026-73248HIGH8.5calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a ...
CVE-2026-73247HIGH8.6Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor...
CVE-2026-73246HIGH7.5Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest...
CVE-2026-67558HIGH8.2The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga...
CVE-2026-66875HIGH8.8In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range...
CVE-2026-66098HIGH7.1The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d...
CVE-2026-29036HIGH7.5cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe...
CVE-2026-19560HIGH8.8Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-19558HIGH7.5Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal...
CVE-2026-19557HIGH8.3Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised...
CVE-2026-19556HIGH8.8Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-18710HIGH8.2A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net...
CVE-2026-66154HIGH8.3An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1...
CVE-2026-66150HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-66149HIGH7.8Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows...
CVE-2026-63177HIGH7.1Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng...
CVE-2026-55676HIGH8.8Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P...
CVE-2026-48763HIGH8.2TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t...
CVE-2026-15606HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-14863HIGH8.8FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at...
CVE-2026-73242HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos...
CVE-2026-73241HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now