2026 CVE Vulnerabilities

47,529 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53414MEDIUM6.5Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic...
CVE-2026-53413HIGH8.3Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting parti...
CVE-2026-48766HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr...
CVE-2026-48495HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS...
CVE-2026-42142HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee...
CVE-2026-19546HIGH8.8A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S...
CVE-2026-19078MEDIUM4.3A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the...
CVE-2026-18640HIGH7.1The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm...
CVE-2026-18639HIGH7.3When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s...
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...
CVE-2026-11814MEDIUM4.9A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in...
CVE-2026-11739MEDIUM4.9A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with...
CVE-2026-11738MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-11737MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ...
CVE-2026-11736LOW1.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ...
CVE-2026-11735LOW1.9A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma...
CVE-2026-11734LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...
CVE-2026-11733LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ...
CVE-2026-73067MEDIUM6.7Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca...
CVE-2026-73066MEDIUM6.8Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse...
CVE-2026-72925MEDIUM6.1SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi...
CVE-2026-72922HIGH8.2AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-72921HIGH8.1SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth...
CVE-2026-72920CRITICAL9.8SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now