2026 CVE Vulnerabilities

49,144 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42317HIGH7GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0...
CVE-2026-37462HIGH7.5An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a...
CVE-2026-36574HIGH7.8A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e...
CVE-2026-44545HIGH7.5daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca...
CVE-2026-37460HIGH7.5Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all...
CVE-2026-35085HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces...
CVE-2026-35084HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ...
CVE-2026-35083HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082HIGH8.8The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient...
CVE-2026-35081HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien...
CVE-2026-35080HIGH8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic...
CVE-2026-35079HIGH8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient...
CVE-2026-35078HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien...
CVE-2026-35077HIGH8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi...
CVE-2026-35076HIGH8.1The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici...
CVE-2026-41032HIGH7.5It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some...
CVE-2026-4035HIGH7.7A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew...
CVE-2026-50031HIGH7.5ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...
CVE-2026-10704HIGH7.3A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func...
CVE-2026-9516HIGH7.5Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter...
CVE-2026-9334HIGH7.3Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i...
CVE-2026-10694HIGH7.3A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i...
CVE-2026-44654HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha...
CVE-2026-42504HIGH7.5Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-40108HIGH7.1GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now