2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47363MEDIUM6.3In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts a...
CVE-2026-47362MEDIUM4.6In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con...
CVE-2026-47361MEDIUM6.4In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission gu...
CVE-2026-44965MEDIUM5.5In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWid...
CVE-2026-44964MEDIUM6.5In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with...
CVE-2026-19229MEDIUM5.5A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona...
CVE-2026-19213MEDIUM4.3A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCo...
CVE-2026-19082HIGH7.5Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count...
CVE-2026-71557MEDIUM6.3go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference name...
CVE-2026-71556HIGH7.1go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera...
CVE-2026-68772HIGH8.5ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke...
CVE-2026-67585HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent...
CVE-2026-66062MEDIUM5.3SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c...
CVE-2026-20348HIGH7.5A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20347HIGH7.5A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20346HIGH7.5A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20345HIGH7.5A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20339HIGH7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20338HIGH7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi...
CVE-2026-20337HIGH7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi...
CVE-2026-19212MEDIUM4.3A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WT...
CVE-2026-19211HIGH7.3A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia...
CVE-2026-17603HIGH8.7Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data...
CVE-2026-17601HIGH8.9A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their ...
CVE-2026-17600HIGH8.7Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now