2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-88832HIGH7.3BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh...
CVE-2026-88830HIGH7.5A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ...
CVE-2026-6668HIGH7.5Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker...
CVE-2026-19888HIGH7.5Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows ...
CVE-2026-96673HIGH7.5Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated ...
CVE-2026-93769HIGH7.2HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegate...
CVE-2026-79310HIGH8.5webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into execut...
CVE-2026-19179HIGH8.2IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database querie...
CVE-2026-18875HIGH7.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook ...
CVE-2026-18490HIGH8.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ...
CVE-2026-18185HIGH7.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive informati...
CVE-2026-18184HIGH7.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...
CVE-2026-18181HIGH8.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and ...
CVE-2026-96609HIGH7.1Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console lo...
CVE-2026-96275HIGH8.8A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host f...
CVE-2026-73591HIGH7.5Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Infor...
CVE-2026-73588HIGH7.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Cr...
CVE-2026-55610HIGH8.7InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and...
CVE-2026-96512HIGH7.8A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps th...
CVE-2026-86683HIGH8.1ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy s...
CVE-2026-86681HIGH7.6ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue t...
CVE-2026-86679HIGH7.1ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue t...
CVE-2026-86678HIGH8.8ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administ...
CVE-2026-86677HIGH8.8ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized S...
CVE-2026-18177HIGH7.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payme...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now