2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-49229HIGH8.3Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f...
CVE-2026-49033HIGH8.4The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb...
CVE-2026-42958HIGH8.4The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s...
CVE-2026-42953HIGH8.4The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ...
CVE-2026-58583HIGH8.4FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc...
CVE-2026-58472HIGH7.1GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string...
CVE-2026-58471HIGH7.1GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f...
CVE-2026-58469HIGH8.7GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s...
CVE-2026-57172HIGH8.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de...
CVE-2026-55635HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ...
CVE-2026-55633HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f...
CVE-2026-55631HIGH7.2DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut...
CVE-2026-53751HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l...
CVE-2026-53730HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en...
CVE-2026-53729HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (...
CVE-2026-53511HIGH8.5calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when...
CVE-2026-50530HIGH7.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl...
CVE-2026-50529HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int...
CVE-2026-50007HIGH7.2Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us...
CVE-2026-49471HIGH8.3Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, ...
CVE-2026-44454HIGH8.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30...
CVE-2026-7017HIGH7.1HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ...
CVE-2026-59708HIGH8.7The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU...
CVE-2026-48958HIGH8.8An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48957HIGH8.8An improper access check allows unauthorized users to access com_privacy datasets.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now