2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-91863HIGH7.5A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and ex...
CVE-2026-89139HIGH8.7Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a comput...
CVE-2026-87858HIGH7.2Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An...
CVE-2026-65654HIGH8.7github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's la...
CVE-2026-65653HIGH8.7github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-pref...
CVE-2026-65652HIGH8.7github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A n...
CVE-2026-65651HIGH8.7temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstra...
CVE-2026-16652HIGH7.1Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated cal...
CVE-2026-16651HIGH8.7temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents...
CVE-2026-92574HIGH8.8A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container t...
CVE-2026-15801HIGH8A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to ...
CVE-2026-47321HIGH7.5The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the ...
CVE-2026-94146HIGH8.8A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file ...
CVE-2026-94144HIGH7.3A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_...
CVE-2026-90860HIGH7.1The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in...
CVE-2026-94143HIGH7.3A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orde...
CVE-2026-94142HIGH8.8A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulner...
CVE-2026-94139HIGH7.4A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an...
CVE-2026-94129HIGH8.8A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105...
CVE-2026-94128HIGH8.8A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of...
CVE-2026-94110HIGH7.3A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library ...
CVE-2026-94044HIGH7.3A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affec...
CVE-2026-88855HIGH8.6Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Jooml...
CVE-2026-94039HIGH7.3A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /ap...
CVE-2026-94038HIGH7.3A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now