2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47613HIGH7.5NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest...
CVE-2026-47612HIGH7.5NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim...
CVE-2026-24255HIGH7.5NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash...
CVE-2026-24253HIGH8.2NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl...
CVE-2026-18830HIGH8.6Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co...
CVE-2026-18788HIGH7.3A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun...
CVE-2026-69263HIGH8.7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation ...
CVE-2026-69262HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1...
CVE-2026-69258HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic...
CVE-2026-69257HIGH7.6Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP ...
CVE-2026-64634HIGH8.4A vulnerability allowing local privilege escalation to the Reporter service context.
CVE-2026-64631HIGH8.5A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-58075HIGH8.7A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag...
CVE-2026-58074HIGH8.6A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
CVE-2026-58071HIGH8.2A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A...
CVE-2026-58067HIGH8.7A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause ...
CVE-2026-56848HIGH7.5A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m...
CVE-2026-18787HIGH8.8A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi...
CVE-2026-15314HIGH7.5Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT...
CVE-2026-15307HIGH8.8An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse...
CVE-2026-69252HIGH7.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil...
CVE-2026-69100HIGH8.8LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i...
CVE-2026-25292HIGH7.6Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration...
CVE-2026-25288HIGH7.4Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084HIGH7.5Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now