2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6726HIGH7.9An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker wi...
CVE-2026-67180HIGH8.4Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing ...
CVE-2026-67179HIGH7.8Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop...
CVE-2026-56721HIGH8.8CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference...
CVE-2026-56720MEDIUM5.3CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ...
CVE-2026-53416HIGH7.1Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca...
CVE-2026-53415HIGH8.3Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code executio...
CVE-2026-53414MEDIUM6.5Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic...
CVE-2026-53413HIGH8.3Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting parti...
CVE-2026-48766HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr...
CVE-2026-48495HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS...
CVE-2026-42142HIGH7.1TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee...
CVE-2026-19546HIGH8.8A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S...
CVE-2026-19078MEDIUM4.3A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the...
CVE-2026-18640HIGH7.1The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm...
CVE-2026-18639HIGH7.3When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s...
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...
CVE-2026-11814MEDIUM4.9A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in...
CVE-2026-11739MEDIUM4.9A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with...
CVE-2026-11738MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-11737MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ...
CVE-2026-11736LOW1.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ...
CVE-2026-11735LOW1.9A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma...
CVE-2026-11734LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now