2026 CVE Vulnerabilities

46,946 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58472HIGH7.1GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string...
CVE-2026-58471HIGH7.1GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f...
CVE-2026-58469HIGH8.7GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s...
CVE-2026-57172HIGH8.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de...
CVE-2026-55635HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ...
CVE-2026-55633HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f...
CVE-2026-55631HIGH7.2DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut...
CVE-2026-53751HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l...
CVE-2026-53730HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en...
CVE-2026-53729HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (...
CVE-2026-53511HIGH8.5calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when...
CVE-2026-50530HIGH7.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl...
CVE-2026-50529HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int...
CVE-2026-50007HIGH7.2Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us...
CVE-2026-49471HIGH8.3Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, ...
CVE-2026-44454HIGH8.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30...
CVE-2026-7017HIGH7.1HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ...
CVE-2026-59708HIGH8.7The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU...
CVE-2026-48958HIGH8.8An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48957HIGH8.8An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48948HIGH8.8An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-57851HIGH8.5MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo...
CVE-2026-23698HIGH8.6Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur...
CVE-2026-23697HIGH8.8Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ...
CVE-2026-14904HIGH7.1AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now