2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-76087HIGH8.2Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submi...
CVE-2026-76086HIGH8.5Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings ...
CVE-2026-75131HIGH7.8NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local use...
CVE-2026-61814HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok...
CVE-2026-61695HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S...
CVE-2026-59990HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes...
CVE-2026-91775HIGH7.4LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import war...
CVE-2026-86938HIGH7.3A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code ...
CVE-2026-86926HIGH7.8A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously...
CVE-2026-96808HIGH7.4In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi...
CVE-2026-96804HIGH8.8MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security contr...
CVE-2026-96775HIGH8.8MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when...
CVE-2026-96756HIGH8.1orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to e...
CVE-2026-96656HIGH7.2Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The pr...
CVE-2026-96514HIGH7.3A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogi...
CVE-2026-96513HIGH7.3A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the fil...
CVE-2026-95847HIGH8.8Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as q...
CVE-2026-95846HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will messa...
CVE-2026-95845HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending pe...
CVE-2026-95844HIGH8.7Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic ...
CVE-2026-95843HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter th...
CVE-2026-95842HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and...
CVE-2026-93349HIGH8.8Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows...
CVE-2026-88832HIGH7.3BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh...
CVE-2026-88830HIGH7.5A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now