2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93382HIGH8.8Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-93381HIGH8.8Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging soc...
CVE-2026-93377HIGH8.8Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to ...
CVE-2026-93375HIGH8.1Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker...
CVE-2026-86049HIGH7.1Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jup...
CVE-2026-77615HIGH8.7Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Op...
CVE-2026-76154HIGH7.3A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role...
CVE-2026-68537HIGH7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve...
CVE-2026-68523HIGH7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve...
CVE-2026-54916HIGH8.8NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abse...
CVE-2026-54597HIGH8.3ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-54596HIGH8.1ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-54510HIGH7.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the...
CVE-2026-54354HIGH8.2MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran...
CVE-2026-54339HIGH7.7Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe...
CVE-2026-52483HIGH8.8The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(...
CVE-2026-50277HIGH7.5dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggag...
CVE-2026-50275HIGH7.5The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddt...
CVE-2026-48977HIGH7.7OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() pro...
CVE-2026-15815HIGH8.8Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug...
CVE-2026-93337HIGH7.8NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows loc...
CVE-2026-92943HIGH8.1Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for ...
CVE-2026-54716HIGH7.5Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earli...
CVE-2026-54692HIGH7.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-50285HIGH7.5Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now