2026 CVE Vulnerabilities

67,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93595MEDIUM6.5ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI...
CVE-2026-93594HIGH8.1ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru...
CVE-2026-93593HIGH8.1ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b...
CVE-2026-93592HIGH7.5vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, ...
CVE-2026-93591HIGH7.6SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values...
CVE-2026-93590LOW3.7ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec...
CVE-2026-93589LOW3.7ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t...
CVE-2026-93588LOW3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re...
CVE-2026-93587LOW3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU...
CVE-2026-93586LOW2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau...
CVE-2026-93560HIGH7.5A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l...
CVE-2026-93504MEDIUM6.3A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se...
CVE-2026-93019CRITICAL9.1Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa...
CVE-2026-93018MEDIUM5.5Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas...
CVE-2026-88623HIGH7.5NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us...
CVE-2026-88622HIGH8.8NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
CVE-2026-79294MEDIUM6.1Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi...
CVE-2026-62282MEDIUM6.5OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int...
CVE-2026-93492MEDIUM5.3A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi...
CVE-2026-93491HIGH7.5A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli...
CVE-2026-93488HIGH7.5A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because...
CVE-2026-28199LOW3.3An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly...
CVE-2026-28198HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp...
CVE-2026-28197HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now