2026 CVE Vulnerabilities

51,070 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8345HIGH8.8A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the funct...
CVE-2026-43913HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organiz...
CVE-2026-43912HIGH8.7Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a group...
CVE-2026-43911HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t...
CVE-2026-34963HIGH7.8barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe...
CVE-2026-8344HIGH8.8A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function ...
CVE-2026-43897HIGH8.7Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. The...
CVE-2026-43893HIGH8.2exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifToo...
CVE-2026-43890HIGH7.7Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API end...
CVE-2026-43888HIGH8.7Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extract...
CVE-2026-43887HIGH7.3Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section perm...
CVE-2026-43886HIGH8.2Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface....
CVE-2026-43885HIGH7.7WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read API...
CVE-2026-43884HIGH7.7WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsyn...
CVE-2026-43873HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.ph...
CVE-2026-42564HIGH8.2jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulner...
CVE-2026-42046HIGH7.8libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas...
CVE-2026-34961HIGH7.7barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing val...
CVE-2026-34960HIGH7.1barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_m...
CVE-2026-43874HIGH7.2WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the Y...
CVE-2026-43668HIGH7.5A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7....
CVE-2026-43661HIGH7.5A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7....
CVE-2026-43660HIGH7.5A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, ...
CVE-2026-43658HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.1...
CVE-2026-43656HIGH7.3An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now