2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100757——Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115....
CVE-2026-100756——Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4,...
CVE-2026-95520HIGH7.1A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared R...
CVE-2026-87748HIGH8.8Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This ...
CVE-2026-85520CRITICAL9.3Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the ...
CVE-2026-73597MEDIUM6.5Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (C...
CVE-2026-73596LOW3.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource...
CVE-2026-73595MEDIUM4.7Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Downl...
CVE-2026-73594MEDIUM6.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Impr...
CVE-2026-73593LOW3Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerabil...
CVE-2026-66083——The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user c...
CVE-2026-41875MEDIUM6.9Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special websi...
CVE-2026-102507MEDIUM5.7Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler tha...
CVE-2026-102497——The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model grou...
CVE-2026-102496——Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a maliciou...
CVE-2026-102495——Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make pars...
CVE-2026-101266LOW1.3A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire ch...
CVE-2026-95509HIGH8.8Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buff...
CVE-2026-96423MEDIUM5.5X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96422MEDIUM5.5Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96421MEDIUM5.5USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96420MEDIUM4.7Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96419MEDIUM5.5Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
CVE-2026-96418MEDIUM5.5TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96417MEDIUM5.5RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now