2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-84447HIGH7.5libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden referenc...
CVE-2026-84446HIGH7.5libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list ...
CVE-2026-84444HIGH7.4libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, he...
CVE-2026-84398HIGH7.5CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An att...
CVE-2026-84384HIGH7.5libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata...
CVE-2026-81944HIGH7.5PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont...
CVE-2026-81942HIGH8.8PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont...
CVE-2026-7006HIGH7.3Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege ...
CVE-2026-67549HIGH7.6OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-63638HIGH8.3OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-63422HIGH7.8OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-63419HIGH7.8OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-54148HIGH8.1http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid...
CVE-2026-11381HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i...
CVE-2026-11378HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-11375HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-10853HIGH8.8IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb...
CVE-2026-10751HIGH7.5IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati...
CVE-2026-10744HIGH7.5IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-10575HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he...
CVE-2026-10030HIGH7.1IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz...
CVE-2026-93659HIGH8.7Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a...
CVE-2026-93658HIGH7uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ...
CVE-2026-93657HIGH7.5hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R...
CVE-2026-93652HIGH7.5Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now