2026 CVE Vulnerabilities

68,107 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93589LOW3.7ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t...
CVE-2026-93588LOW3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re...
CVE-2026-93587LOW3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU...
CVE-2026-93586LOW2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau...
CVE-2026-93560HIGH7.5A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l...
CVE-2026-93504MEDIUM6.3A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se...
CVE-2026-93019CRITICAL9.1Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa...
CVE-2026-93018MEDIUM5.5Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas...
CVE-2026-88623HIGH7.5NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us...
CVE-2026-88622HIGH8.8NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
CVE-2026-79294MEDIUM6.1Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi...
CVE-2026-62282MEDIUM6.5OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int...
CVE-2026-93492MEDIUM5.3A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi...
CVE-2026-93491HIGH7.5A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli...
CVE-2026-93488HIGH7.5A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because...
CVE-2026-28199LOW3.3An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly...
CVE-2026-28198HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp...
CVE-2026-28197HIGH8.8An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...
CVE-2026-93578MEDIUM5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP...
CVE-2026-93575HIGH7.5A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ...
CVE-2026-93572HIGH7.5A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin...
CVE-2026-93563HIGH7.5A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd...
CVE-2026-93561MEDIUM6.5A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ...
CVE-2026-81627HIGH8.2A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now