2026 CVE Vulnerabilities

47,529 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-20702HIGH8.9Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information ...
CVE-2026-20349HIGH8.6A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar...
CVE-2026-18247MEDIUM5.3A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could al...
CVE-2026-12571CRITICAL9.8An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
CVE-2026-9214MEDIUM4.3Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected t...
CVE-2026-73080CRITICAL9.3SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re...
CVE-2026-73079HIGH8.5Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0...
CVE-2026-73078HIGH8.6Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runti...
CVE-2026-73077HIGH8.4Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vi...
CVE-2026-73076HIGH8.4Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimbal...
CVE-2026-73075MEDIUM4.6Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupw...
CVE-2026-73074HIGH7.1Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen va...
CVE-2026-73072HIGH8.5Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] ...
CVE-2026-73071LOW3.3Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta...
CVE-2026-73070MEDIUM6.8Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c acce...
CVE-2026-73069CRITICAL9.1Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad...
CVE-2026-73068MEDIUM5.9ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-6727MEDIUM5.9A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a...
CVE-2026-6726HIGH7.9An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi...
CVE-2026-67180HIGH8.4Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing ...
CVE-2026-67179HIGH7.8Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop...
CVE-2026-56721HIGH8.8CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference...
CVE-2026-56720MEDIUM5.3CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ...
CVE-2026-53416HIGH7.1Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca...
CVE-2026-53415HIGH8.3Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code executio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now