2026 CVE Vulnerabilities

68,701 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93676LOW3.2xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio...
CVE-2026-93660MEDIUM6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe...
CVE-2026-93659HIGH8.1Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a...
CVE-2026-93658HIGH7uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ...
CVE-2026-93657HIGH7.5hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R...
CVE-2026-93653MEDIUM5.5A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t...
CVE-2026-93652HIGH7.5Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do...
CVE-2026-93576HIGH7.5A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed ...
CVE-2026-93573MEDIUM6.5A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` ...
CVE-2026-93569HIGH8.2A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 con...
CVE-2026-93568HIGH7.5A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTT...
CVE-2026-93567HIGH7.5A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly u...
CVE-2026-93566MEDIUM6.5A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that include...
CVE-2026-93565HIGH7.5A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes fr...
CVE-2026-93564HIGH7.5A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticat...
CVE-2026-93558HIGH7.5A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnera...
CVE-2026-93506MEDIUM6.3A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/...
CVE-2026-93505LOW3.5A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-...
CVE-2026-85511MEDIUM4.2A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oau...
CVE-2026-77929HIGH8.8ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c...
CVE-2026-77928MEDIUM6.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ...
CVE-2026-77927MEDIUM6.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ...
CVE-2026-25684MEDIUM4.4A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatio...
CVE-2026-16515MEDIUM4.7net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rul...
CVE-2026-16514MEDIUM4.3gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now