2026 CVE Vulnerabilities

45,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41154HIGH7.8Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. ...
CVE-2026-34196HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a...
CVE-2026-57850HIGH8.7RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l...
CVE-2026-55827HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-...
CVE-2026-55789HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app...
CVE-2026-55466HIGH8.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP...
CVE-2026-55452HIGH7.3Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ...
CVE-2026-55377HIGH8.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-...
CVE-2026-11321HIGH7.1The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ...
CVE-2026-6212HIGH8.8Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri...
CVE-2026-61461HIGH8.8Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ...
CVE-2026-61460HIGH8.8Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,...
CVE-2026-55516HIGH7.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} ch...
CVE-2026-55460HIGH7.1Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and u...
CVE-2026-54329HIGH7.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request ...
CVE-2026-53450HIGH7.4Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by d...
CVE-2026-53448HIGH7.2Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe...
CVE-2026-56668HIGH8.1ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur...
CVE-2026-56667HIGH7.3ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi...
CVE-2026-55672HIGH7.4ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan...
CVE-2026-59190HIGH8.7grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5...
CVE-2026-59162HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses...
CVE-2026-59161HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w...
CVE-2026-56675HIGH8.39Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce...
CVE-2026-55687HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possib...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now