2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10709HIGH7.8A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab...
CVE-2026-14838HIGH7.4Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. ...
CVE-2026-67243HIGH8.6freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig...
CVE-2026-18759HIGH8.5The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication...
CVE-2026-18755HIGH7.3A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di...
CVE-2026-64563HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r...
CVE-2026-64562HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr...
CVE-2026-64561HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m...
CVE-2026-16623HIGH8The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g...
CVE-2026-16881HIGH8.7A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component...
CVE-2026-42169HIGH7.3A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f...
CVE-2026-14818HIGH7.2A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi...
CVE-2026-6837HIGH7.2A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions...
CVE-2026-56846HIGH7.5A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor...
CVE-2026-56845HIGH7.5An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur...
CVE-2026-66326HIGH8.8Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66318HIGH8.1Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ...
CVE-2026-66315HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66312HIGH8.8Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66310HIGH7.1External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat...
CVE-2026-65802HIGH7.4External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat...
CVE-2026-62870HIGH8.8Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-67978HIGH7.5An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin...
CVE-2026-48399HIGH7.5Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a...
CVE-2026-69249HIGH8.7python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now