2026 CVE Vulnerabilities

50,972 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8964HIGH7.5Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8963HIGH7.5Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8962HIGH8.1Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thund...
CVE-2026-8960HIGH7.5Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8958HIGH8.6Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi...
CVE-2026-8957HIGH8.8Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140....
CVE-2026-8955HIGH8.8Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu...
CVE-2026-8954HIGH7.5Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 15...
CVE-2026-8952HIGH8.8Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15...
CVE-2026-8949HIGH7.5Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde...
CVE-2026-8947HIGH7.3Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,...
CVE-2026-8946HIGH7.5Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir...
CVE-2026-8945HIGH7.5Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-42100HIGH7.5Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ...
CVE-2026-42099HIGH7.5Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica...
CVE-2026-42098HIGH8.7Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An...
CVE-2026-42097HIGH8.8Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ...
CVE-2026-42096HIGH8.8Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per...
CVE-2026-23558HIGH7.8The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ...
CVE-2026-8912HIGH7.5The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to...
CVE-2026-7571HIGH7.1A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a secur...
CVE-2026-7507HIGH7.5A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could expl...
CVE-2026-7504HIGH8.1A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an atta...
CVE-2026-7307HIGH7.5A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security ...
CVE-2026-8827HIGH8.2The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now