2026 CVE Vulnerabilities

50,981 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34253HIGH8.2A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi...
CVE-2026-46333HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ...
CVE-2026-41552HIGH7.5PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sani...
CVE-2026-41964HIGH8.4Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabili...
CVE-2026-6403HIGH7.5The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is...
CVE-2026-6228HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ...
CVE-2026-44088HIGH8.6SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t...
CVE-2026-8654HIGH8.7Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat...
CVE-2026-4094HIGH8.1The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du...
CVE-2026-41702HIGH7VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a...
CVE-2026-43490HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher...
CVE-2026-28761HIGH8.5Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a...
CVE-2026-7373HIGH8.5Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr...
CVE-2026-2652HIGH8.6A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when...
CVE-2026-0432HIGH8.5Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev...
CVE-2026-44671HIGH7.5ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was di...
CVE-2026-45370HIGH7.7python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.p...
CVE-2026-45369HIGH8.3python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_...
CVE-2026-44700HIGH8.7Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica...
CVE-2026-44678HIGH7.1Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{...
CVE-2026-44673HIGH7.5libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an ...
CVE-2026-44647HIGH7.1OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected bou...
CVE-2026-42847HIGH7.1ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) ...
CVE-2026-42327HIGH8.7rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re...
CVE-2026-8629HIGH8.6Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only acc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now