2026 CVE Vulnerabilities

48,075 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-38640HIGH7.5A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De...
CVE-2026-38637HIGH7.5An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S...
CVE-2026-37452HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-12473HIGH8.3Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter wit...
CVE-2026-57520HIGH7.1Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi...
CVE-2026-55960HIGH7.5Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub...
CVE-2026-55958HIGH7.5Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th...
CVE-2026-46602HIGH7.5The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont...
CVE-2026-46601HIGH7.5The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
CVE-2026-37454HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37453HIGH7.5Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit...
CVE-2026-37149HIGH7.7GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2026-12340HIGH7.5Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si...
CVE-2026-11310HIGH7.5X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on...
CVE-2026-10512HIGH7.5The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so...
CVE-2026-10097HIGH7.5wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t...
CVE-2026-56790HIGH7.3CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() funct...
CVE-2026-56789HIGH7.1RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow...
CVE-2026-56788HIGH7.1RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RI...
CVE-2026-56787HIGH7.5RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:...
CVE-2026-56771HIGH8.5NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows ...
CVE-2026-56770HIGH7.5libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences ...
CVE-2026-56769HIGH8.5Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili...
CVE-2026-56768HIGH8.8Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthe...
CVE-2026-56767HIGH8.8Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API ha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now