2026 CVE Vulnerabilities

50,972 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8370HIGH8.5Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ...
CVE-2026-8073HIGH7.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del...
CVE-2026-41470HIGH8.2LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at...
CVE-2026-8604HIGH8.8In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic...
CVE-2026-6009HIGH8.7Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow...
CVE-2026-47107HIGH8.6Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ...
CVE-2026-33633HIGH8.8Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat...
CVE-2026-47358HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded...
CVE-2026-47357HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem...
CVE-2026-47356HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi...
CVE-2026-36828HIGH8.8A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin...
CVE-2026-5804HIGH8.4An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). T...
CVE-2026-31069HIGH8.8BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle...
CVE-2026-47100HIGH8.7Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public c...
CVE-2026-43634HIGH8.7HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers ...
CVE-2026-8975HIGH8.8Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence...
CVE-2026-8974HIGH8.8Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruptio...
CVE-2026-8973HIGH8.8Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2026-8972HIGH8.8Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 1...
CVE-2026-8970HIGH8.8Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunder...
CVE-2026-8969HIGH8.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8968HIGH7.5Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef...
CVE-2026-8967HIGH7.5Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 15...
CVE-2026-8966HIGH7.5Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8965HIGH7.5Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now