2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59205HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigge...
CVE-2026-59204HIGH7.5Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component...
CVE-2026-59203HIGH7.5Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a n...
CVE-2026-59199HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-o...
CVE-2026-59198HIGH7.5Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer w...
CVE-2026-55651HIGH7.1Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in ...
CVE-2026-15392HIGH7.7DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The co...
CVE-2026-14504HIGH8.2An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on ...
CVE-2026-12707HIGH7.5Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p...
CVE-2026-12659HIGH8.7A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of e...
CVE-2026-12523HIGH7.5Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by mea...
CVE-2026-11917HIGH7.2A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of fi...
CVE-2026-11403HIGH8.7A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to...
CVE-2026-9653HIGH8.7A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper va...
CVE-2026-9140HIGH8.7A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP un...
CVE-2026-8590HIGH8.7Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Cons...
CVE-2026-60114HIGH8.7Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attacke...
CVE-2026-58477HIGH7.5Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth...
CVE-2026-58476HIGH8.1Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al...
CVE-2026-51105HIGH7.5Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t...
CVE-2026-15736HIGH8.3Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of ...
CVE-2026-15696HIGH8.8A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the...
CVE-2026-15695HIGH8.8A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file...
CVE-2026-15694HIGH8.8A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/S...
CVE-2026-10714HIGH8.8A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now