2026 CVE Vulnerabilities

45,452 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59712HIGH8.6Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ...
CVE-2026-57573HIGH8.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ...
CVE-2026-55727HIGH7.5A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14...
CVE-2026-55574HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou...
CVE-2026-54765HIGH8.5Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa...
CVE-2026-54234HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ...
CVE-2026-42331HIGH7.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u...
CVE-2026-25271HIGH7Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec...
CVE-2026-25268HIGH8.8Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2026-21383HIGH7.1Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value fo...
CVE-2026-21379HIGH7.8Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-14471HIGH8.6Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g...
CVE-2026-14468HIGH7.7HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that...
CVE-2026-14536HIGH8.8Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack...
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...
CVE-2026-55380HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t...
CVE-2026-55379HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f...
CVE-2026-54060HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ...
CVE-2026-54059HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P...
CVE-2026-13753HIGH7.5A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmwa...
CVE-2026-43825HIGH7.3Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document c...
CVE-2026-40140HIGH7.5BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ...
CVE-2026-40138HIGH8.1A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri...
CVE-2026-59196HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste...
CVE-2026-59195HIGH8.2pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now