2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-64636HIGH7.7An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea...
CVE-2026-19082HIGH7.5Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count...
CVE-2026-71556HIGH7.1go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera...
CVE-2026-68772HIGH8.5ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke...
CVE-2026-67585HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent...
CVE-2026-20348HIGH7.5A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20347HIGH7.5A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20346HIGH7.5A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20345HIGH7.5A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c...
CVE-2026-20339HIGH7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do...
CVE-2026-20338HIGH7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi...
CVE-2026-20337HIGH7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi...
CVE-2026-19211HIGH7.3A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia...
CVE-2026-17603HIGH8.7Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data...
CVE-2026-17601HIGH8.9A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their ...
CVE-2026-17600HIGH8.7Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio...
CVE-2026-17594HIGH8.2Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th...
CVE-2026-17593HIGH7.2An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi...
CVE-2026-14644HIGH8.6Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with...
CVE-2026-18497HIGH7.1A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p...
CVE-2026-15570HIGH7.1An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245...
CVE-2026-66494HIGH8.7Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut...
CVE-2026-15816HIGH7.5A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs...
CVE-2026-71559HIGH7.5Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de...
CVE-2026-54218HIGH8.8Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now