2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65668HIGH8.8Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo...
CVE-2026-62918HIGH7.5Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ...
CVE-2026-49163HIGH8.8Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a...
CVE-2026-8325HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma...
CVE-2026-7867HIGH7.8A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec...
CVE-2026-7406HIGH7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference...
CVE-2026-71488HIGH7.5league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf...
CVE-2026-71476HIGH8.7Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel...
CVE-2026-71445HIGH8.2AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occu...
CVE-2026-71327HIGH7.6Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes...
CVE-2026-71324HIGH7Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default H...
CVE-2026-70640HIGH7.3llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap...
CVE-2026-70638HIGH8.5llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th...
CVE-2026-70636HIGH8.7Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th...
CVE-2026-70635HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica...
CVE-2026-70634HIGH8.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers...
CVE-2026-70633HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres...
CVE-2026-70632HIGH8.5FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G...
CVE-2026-70628HIGH8.5FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit...
CVE-2026-70559HIGH8.7Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t...
CVE-2026-70557HIGH7.1diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of ...
CVE-2026-67687HIGH8.8Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol...
CVE-2026-67621HIGH7.6Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf...
CVE-2026-67434HIGH7.3PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13....
CVE-2026-67422HIGH7.5pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now