2026 CVE Vulnerabilities

47,574 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-36912HIGH7.5A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3...
CVE-2026-58263HIGH7.2Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in...
CVE-2026-55660HIGH7.6Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po...
CVE-2026-55153HIGH7.1mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool....
CVE-2026-54074HIGH7.8Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne...
CVE-2026-50521HIGH8.3Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-58593HIGH8.7NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound ...
CVE-2026-58592HIGH8.9Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaS...
CVE-2026-14265HIGH8.8Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t...
CVE-2026-58451HIGH7.1Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to...
CVE-2026-49119HIGH8.7Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all...
CVE-2026-41121HIGH7.8Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin...
CVE-2026-13760HIGH7.3OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor...
CVE-2026-57736HIGH7.4Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi...
CVE-2026-57723HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal....
CVE-2026-54428HIGH7.5Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an...
CVE-2026-49091HIGH8Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin...
CVE-2026-46680HIGH7.8containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched...
CVE-2026-58454HIGH7.7JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ...
CVE-2026-58452HIGH8.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ...
CVE-2026-57516HIGH8.8Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a...
CVE-2026-56150HIGH7.5Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces...
CVE-2026-54399HIGH7.5Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ...
CVE-2026-20244HIGH7.5A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20243HIGH7.5A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now