2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47266HIGH8.7Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing...
CVE-2026-47123HIGH7.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin...
CVE-2026-46599HIGH7.5The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit...
CVE-2026-46527HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has c...
CVE-2026-46385HIGH7.5iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro...
CVE-2026-46384HIGH7.5iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit val...
CVE-2026-45352HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i...
CVE-2026-45149HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0....
CVE-2026-44422HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on...
CVE-2026-44421HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h...
CVE-2026-44420HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h...
CVE-2026-44285HIGH7.7FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo...
CVE-2026-49382HIGH7.8In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-49374HIGH7.6In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49373HIGH8.8In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49372HIGH7.5In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371HIGH8.2In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49370HIGH7.5In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49367HIGH8.8In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49366HIGH7.8In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-47740HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or...
CVE-2026-46372HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44648HIGH7.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-42941HIGH8.7The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c...
CVE-2026-42929HIGH8.7Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now