2026 CVE Vulnerabilities

47,646 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13760HIGH7.3OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor...
CVE-2026-57736HIGH7.4Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi...
CVE-2026-57723HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal....
CVE-2026-54428HIGH7.5Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an...
CVE-2026-49091HIGH8Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin...
CVE-2026-46680HIGH7.8containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched...
CVE-2026-58454HIGH7.7JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ...
CVE-2026-58452HIGH8.8JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ...
CVE-2026-57516HIGH8.8Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a...
CVE-2026-56150HIGH7.5Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces...
CVE-2026-54399HIGH7.5Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ...
CVE-2026-20244HIGH7.5A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20243HIGH7.5A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20217HIGH7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20216HIGH7.5A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau...
CVE-2026-20215HIGH7.5A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20214HIGH7.5A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20213HIGH7.5A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co...
CVE-2026-20191HIGH7.5A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a ...
CVE-2026-8857HIGH8.8A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTime...
CVE-2026-58036HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-24266HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A ...
CVE-2026-24264HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highl...
CVE-2026-24260HIGH8.5NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use ra...
CVE-2026-24251HIGH7.8NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now