2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6758HIGH7.5Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150...
CVE-2026-6757MEDIUM6.3Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.1...
CVE-2026-6756HIGH7.5Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
CVE-2026-6755MEDIUM6.5Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6754HIGH7.5Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire...
CVE-2026-6753HIGH7.3Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, ...
CVE-2026-6752HIGH7.3Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, ...
CVE-2026-6751HIGH7.3Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ...
CVE-2026-6750HIGH8.8Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115....
CVE-2026-6749HIGH7.5Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in ...
CVE-2026-6748CRITICAL9.8Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ...
CVE-2026-6747HIGH7.5Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150...
CVE-2026-6746HIGH7.5Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef...
CVE-2026-40520HIGH8.8FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun...
CVE-2026-32147MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftp...
CVE-2026-41039HIGH7.5This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i...
CVE-2026-41038HIGH8.8This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b...
CVE-2026-6553HIGH7.5Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u...
CVE-2026-41037HIGH8.8This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi...
CVE-2026-41036HIGH8.8This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage...
CVE-2026-3317MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present i...
CVE-2026-39467HIGH7.2Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th...
CVE-2026-6712MEDIUM4.4The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2026-6711MEDIUM6.1The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all...
CVE-2026-6703MEDIUM4.3The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now