2026 CVE Vulnerabilities

48,542 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-36213HIGH7.8An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e...
CVE-2026-8357HIGH7.8LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very...
CVE-2026-6040HIGH7.3A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f...
CVE-2026-47777HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ...
CVE-2026-9863HIGH8.8Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta...
CVE-2026-5038HIGH7.5Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d...
CVE-2026-6517HIGH7.7Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were...
CVE-2026-5242HIGH8.8Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code...
CVE-2026-5233HIGH7.1Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issu...
CVE-2026-5230HIGH7.1Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Inco...
CVE-2026-5079HIGH7.5Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi...
CVE-2026-49111HIGH8.8Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe...
CVE-2026-49064HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da...
CVE-2026-49062HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex...
CVE-2026-34026HIGH7.1Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume...
CVE-2026-34024HIGH8.6The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple...
CVE-2026-34023HIGH7.1The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability...
CVE-2026-34022HIGH7.1The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptogra...
CVE-2026-34021HIGH8.6The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t...
CVE-2026-12057HIGH7.8When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d...
CVE-2026-50100HIGH8.5Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation v...
CVE-2026-11860HIGH7.5Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi...
CVE-2026-12222HIGH8A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the ...
CVE-2026-12221HIGH8A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/u...
CVE-2026-12220HIGH8A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now