2026 CVE Vulnerabilities

47,201 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...
CVE-2026-55380HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t...
CVE-2026-55379HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f...
CVE-2026-54060HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ...
CVE-2026-54059HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P...
CVE-2026-13753HIGH7.5A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmwa...
CVE-2026-43825HIGH7.3Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document c...
CVE-2026-40140HIGH7.5BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ...
CVE-2026-40138HIGH8.1A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri...
CVE-2026-59196HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste...
CVE-2026-59195HIGH8.2pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc...
CVE-2026-59194HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch...
CVE-2026-58380HIGH7.8A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ...
CVE-2026-13698HIGH7.5A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a...
CVE-2026-13708HIGH7.5Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_...
CVE-2026-13705HIGH7.1Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bi...
CVE-2026-6901HIGH8.4Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P...
CVE-2026-58226HIGH8.7Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun...
CVE-2026-56810HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni...
CVE-2026-4249HIGH8.6The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient...
CVE-2026-49297HIGH8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object ...
CVE-2026-49042HIGH7.3Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, fr...
CVE-2026-46588HIGH7.3Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 t...
CVE-2026-46587HIGH7.3Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 t...
CVE-2026-44937HIGH8.2Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now