2026 CVE Vulnerabilities

48,527 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53840HIGH7.1OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards ...
CVE-2026-50656HIGH7Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl...
CVE-2026-47964HIGH7.8DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ...
CVE-2026-47749HIGH7.8stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima...
CVE-2026-10748HIGH8.6An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi...
CVE-2026-44932HIGH8.8Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac...
CVE-2026-42089HIGH8.6Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i...
CVE-2026-24228HIGH7.8NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. ...
CVE-2026-24155HIGH7.8NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil...
CVE-2026-10649HIGH8.6A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r...
CVE-2026-48780HIGH8.2Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address cou...
CVE-2026-47684HIGH7.7Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version...
CVE-2026-12398HIGH7.5A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (...
CVE-2026-11317HIGH8.7A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when ...
CVE-2026-10640HIGH7.1Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_...
CVE-2026-10638HIGH7.5subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data...
CVE-2026-10637HIGH7.1subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned s...
CVE-2026-0647HIGH8.8An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability ...
CVE-2026-0646HIGH8.7A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol ...
CVE-2026-12328HIGH8.1Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbir...
CVE-2026-12327HIGH8.1Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these...
CVE-2026-12326HIGH8.1Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption a...
CVE-2026-12324HIGH7.3Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef...
CVE-2026-12318HIGH7.3Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder...
CVE-2026-12317HIGH7.5Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now