2026 CVE Vulnerabilities

46,944 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55076HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-51937HIGH7.5An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp...
CVE-2026-14895HIGH7.5String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri...
CVE-2026-14380HIGH8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass...
CVE-2026-55418HIGH8.6FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr...
CVE-2026-55408HIGH8.4Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu...
CVE-2026-55075HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-54607HIGH7.7FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid...
CVE-2026-54602HIGH7.1FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t...
CVE-2026-49229HIGH8.3Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f...
CVE-2026-49033HIGH8.4The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb...
CVE-2026-42958HIGH8.4The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s...
CVE-2026-42953HIGH8.4The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ...
CVE-2026-58583HIGH8.4FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc...
CVE-2026-58472HIGH7.1GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string...
CVE-2026-58471HIGH7.1GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f...
CVE-2026-58469HIGH8.7GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s...
CVE-2026-57172HIGH8.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de...
CVE-2026-55635HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ...
CVE-2026-55633HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f...
CVE-2026-55631HIGH7.2DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut...
CVE-2026-53751HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l...
CVE-2026-53730HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en...
CVE-2026-53729HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (...
CVE-2026-53511HIGH8.5calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now