2026 CVE Vulnerabilities

47,538 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13054HIGH7.2A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke...
CVE-2026-13053HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe...
CVE-2026-13050HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ...
CVE-2026-57100HIGH8.8Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to...
CVE-2026-54998HIGH8.8Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499HIGH8.8Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-12413HIGH7.5An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou...
CVE-2026-58460HIGH7.7react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat...
CVE-2026-52192HIGH7.5An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead...
CVE-2026-52191HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52189HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-38972HIGH7.8Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not...
CVE-2026-38970HIGH7.5pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The pars...
CVE-2026-59098HIGH7.1LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea...
CVE-2026-59096HIGH8.2Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ...
CVE-2026-59095HIGH8.3LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker...
CVE-2026-59094HIGH8.7Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume...
CVE-2026-59093HIGH8.8Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted...
CVE-2026-58578HIGH7.1LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo...
CVE-2026-58467HIGH8.2Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ...
CVE-2026-52187HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-7311HIGH8.1The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in...
CVE-2026-58465HIGH8.7Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand...
CVE-2026-8699HIGH7A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5...
CVE-2026-55952HIGH7.5The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now