2026 CVE Vulnerabilities

67,767 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32837MEDIUM5.1miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi...
CVE-2026-32836MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me...
CVE-2026-30707HIGH8.1An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v...
CVE-2026-25936HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth...
CVE-2026-3207CRITICAL9.8Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
CVE-2026-25790HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25772HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2026-25771HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ...
CVE-2026-22882HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-20726HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-4319CRITICAL9.8A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-32298CRITICAL9.1The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen...
CVE-2026-32297CRITICAL9.3The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or ...
CVE-2026-32296HIGH8.8Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent...
CVE-2026-32295CRITICAL9.3JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
CVE-2026-32294HIGH7JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp...
CVE-2026-32293MEDIUM6.3The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL...
CVE-2026-32292CRITICAL9.3The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede...
CVE-2026-32291HIGH7The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ...
CVE-2026-32290HIGH7The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f...
CVE-2026-25770HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25769CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.1...
CVE-2026-25534CRITICAL9.1### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddri...
CVE-2026-21570HIGH8.8This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ...
CVE-2026-4148HIGH8.8A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now