2026 CVE Vulnerabilities

48,299 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48774HIGH7.5ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC...
CVE-2026-48715HIGH8.8radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai...
CVE-2026-48089HIGH7.1DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc...
CVE-2026-49340HIGH8.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e...
CVE-2026-49339HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6...
CVE-2026-49338HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso...
CVE-2026-49293HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa...
CVE-2026-49291HIGH8.1mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo...
CVE-2026-49290HIGH7.6Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr...
CVE-2026-49287HIGH7.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026...
CVE-2026-49286HIGH8.1PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...
CVE-2026-56211HIGH7.1A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v...
CVE-2026-56210HIGH7.1A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds ...
CVE-2026-56209HIGH7.1An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c...
CVE-2026-56208HIGH7.6A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco...
CVE-2026-49260HIGH8.2PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/...
CVE-2026-3195HIGH7.4A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f...
CVE-2026-52910HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio...
CVE-2026-52909HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device...
CVE-2026-52908HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c...
CVE-2026-4027HIGH7.1A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces...
CVE-2026-4026HIGH8.7A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit...
CVE-2026-49872HIGH8.1Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po...
CVE-2026-49357HIGH8.8Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o...
CVE-2026-48895HIGH7.2URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now