2026 CVE Vulnerabilities

48,561 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9754HIGH7.1An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-9753HIGH8.1The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed ...
CVE-2026-9752HIGH7.1An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO...
CVE-2026-9750HIGH7.1An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe...
CVE-2026-9749HIGH7.1This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran...
CVE-2026-9748HIGH7.1The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st...
CVE-2026-9747HIGH7.1Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
CVE-2026-9746HIGH7.1When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which...
CVE-2026-9743HIGH7.1In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines...
CVE-2026-9741HIGH7.1A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F...
CVE-2026-9740HIGH8.7A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ...
CVE-2026-46374HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-46373HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-34713HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34712HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-34711HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo...
CVE-2026-48292HIGH7.8Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-48291HIGH7.8Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-47960HIGH7.4ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference...
CVE-2026-47959HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerabili...
CVE-2026-47955HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could...
CVE-2026-47952HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit...
CVE-2026-47937HIGH7.7Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulne...
CVE-2026-47932HIGH8.8ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-47931HIGH8.4ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now