2026 CVE Vulnerabilities

68,112 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0866——Rejected reason: After the publication of the PoC by the researcher and further analysis, we have determined that this i...
CVE-2026-3479NONE0DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same secur...
CVE-2026-31965HIGH8.2HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-31964HIGH7.5HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-31963HIGH8.1HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-32634HIGH8.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glance...
CVE-2026-32633CRITICAL9.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/...
CVE-2026-32632MEDIUM5.9Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the...
CVE-2026-32611CRITICAL9.1Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject...
CVE-2026-31962HIGH8.8HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se...
CVE-2026-30704CRITICAL9.1The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hard...
CVE-2026-30703CRITICAL9.8A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX...
CVE-2026-30702CRITICAL9.8The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web manag...
CVE-2026-30701CRITICAL9.1The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure...
CVE-2026-30048MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied inpu...
CVE-2026-29859CRITICAL9.8An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra...
CVE-2026-29858HIGH7.5A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensiti...
CVE-2026-29856HIGH7.5An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regul...
CVE-2026-27135HIGH7.5nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 lib...
CVE-2026-26948MEDIUM4.9Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.9...
CVE-2026-26945MEDIUM5.3Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.1...
CVE-2026-26740HIGH8.2Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToE...
CVE-2026-23270HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingr...
CVE-2026-23269HIGH7.1In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds i...
CVE-2026-23268HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now