2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65400HIGH7.1An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS...
CVE-2026-64665HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ...
CVE-2026-63725HIGH8.6sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta...
CVE-2026-63637HIGH8.6Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter....
CVE-2026-62857HIGH8.8Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the...
CVE-2026-5856HIGH7.1Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack...
CVE-2026-5855HIGH8.7Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt...
CVE-2026-48084HIGH7.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri...
CVE-2026-48081HIGH8.1OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48080HIGH8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48079HIGH7.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48054HIGH8.8OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin ...
CVE-2026-47765HIGH7.1Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints ...
CVE-2026-47194HIGH8.6Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation c...
CVE-2026-45414HIGH8.5Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth...
CVE-2026-45378HIGH7.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-43628HIGH8.5llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample...
CVE-2026-43627HIGH8.5llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ...
CVE-2026-3415HIGH8.7The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio...
CVE-2026-1289HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A maliciou...
CVE-2026-19177HIGH8.3Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ...
CVE-2026-19176HIGH7.5Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render...
CVE-2026-19174HIGH8.8Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-19173HIGH8.3Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the r...
CVE-2026-19172HIGH8.3Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now