2026 CVE Vulnerabilities

67,587 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93594HIGH8.1ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru...
CVE-2026-93593HIGH8.1ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b...
CVE-2026-93592HIGH7.5vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, ...
CVE-2026-93591HIGH7.6SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values...
CVE-2026-93590LOW3.7ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec...
CVE-2026-93589LOW3.7ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t...
CVE-2026-93588LOW3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re...
CVE-2026-93587LOW3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU...
CVE-2026-93586LOW2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau...
CVE-2026-93560HIGH7.5A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l...
CVE-2026-93504MEDIUM6.3A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se...
CVE-2026-93019CRITICAL9.1Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa...
CVE-2026-93018MEDIUM5.5Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas...
CVE-2026-88623HIGH7.5NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us...
CVE-2026-88622HIGH8.8NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
CVE-2026-79294MEDIUM6.1Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi...
CVE-2026-62282MEDIUM6.5OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int...
CVE-2026-93492MEDIUM5.3A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi...
CVE-2026-93491HIGH7.5A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli...
CVE-2026-93488HIGH7.5A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because...
CVE-2026-28199LOW3.3An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly...
CVE-2026-28198HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp...
CVE-2026-28197HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...
CVE-2026-93578MEDIUM5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now