2026 CVE Vulnerabilities

45,440 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47927MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur...
CVE-2026-47748MEDIUM5.5stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima...
CVE-2026-12003MEDIUM5.3To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is...
CVE-2026-9307MEDIUM6.3A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's ...
CVE-2026-10831MEDIUM6.9A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The co...
CVE-2026-10639MEDIUM4.8In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply...
CVE-2026-9507MEDIUM5.1A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijac...
CVE-2026-53900MEDIUM4.3Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument...
CVE-2026-53899MEDIUM6.5Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff...
CVE-2026-12330MEDIUM5.4Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12,...
CVE-2026-12329MEDIUM5.3Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 14...
CVE-2026-12325MEDIUM6.5Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, ...
CVE-2026-12323MEDIUM5.4Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12322MEDIUM5.4Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
CVE-2026-12321MEDIUM5.4JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird...
CVE-2026-12320MEDIUM4.3Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 15...
CVE-2026-12319MEDIUM6.5Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15...
CVE-2026-12313MEDIUM4.7Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi...
CVE-2026-12311MEDIUM4.7Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi...
CVE-2026-12309MEDIUM6.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12308MEDIUM5.3Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12307MEDIUM5.3Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12306MEDIUM5.3Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152...
CVE-2026-12303MEDIUM4.3Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fi...
CVE-2026-12302MEDIUM6.5Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now