2026 CVE Vulnerabilities

47,330 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21379HIGH7.8Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-14471HIGH8.6Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g...
CVE-2026-14468HIGH7.7HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that...
CVE-2026-14536HIGH8.8Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack...
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...
CVE-2026-55380HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t...
CVE-2026-55379HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f...
CVE-2026-54060HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ...
CVE-2026-54059HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P...
CVE-2026-13753HIGH7.5A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmwa...
CVE-2026-43825HIGH7.3Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document c...
CVE-2026-40140HIGH7.5BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ...
CVE-2026-40138HIGH8.1A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri...
CVE-2026-59196HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste...
CVE-2026-59195HIGH8.2pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc...
CVE-2026-59194HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch...
CVE-2026-58380HIGH7.8A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ...
CVE-2026-13698HIGH7.5A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a...
CVE-2026-13708HIGH7.5Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_...
CVE-2026-13705HIGH7.1Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bi...
CVE-2026-6901HIGH8.4Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P...
CVE-2026-58226HIGH8.7Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun...
CVE-2026-56810HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni...
CVE-2026-4249HIGH8.6The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient...
CVE-2026-49297HIGH8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now