2026 CVE Vulnerabilities

51,076 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3609HIGH7.8Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vuln...
CVE-2026-38568HIGH8.1HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on ...
CVE-2026-38566HIGH8.1HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change a...
CVE-2026-36983HIGH7.3D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The man...
CVE-2026-36962HIGH7.3SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve...
CVE-2026-30635HIGH8.1Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via ...
CVE-2026-2393HIGH7.1A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` fun...
CVE-2026-2291HIGH7.3dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS...
CVE-2026-44738HIGH7.7Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page...
CVE-2026-42845HIGH7.7The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-con...
CVE-2026-42843HIGH8.8Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configur...
CVE-2026-42603HIGH8.8OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m...
CVE-2026-42349HIGH8.1Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related auth...
CVE-2026-33362HIGH8.6In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps ...
CVE-2026-33361HIGH7.5In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), a...
CVE-2026-33359HIGH7.5In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion s...
CVE-2026-33357HIGH7.5In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and...
CVE-2026-33356HIGH7.7In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to gl...
CVE-2026-31254HIGH7.3The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection ...
CVE-2026-31253HIGH7.3The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an ins...
CVE-2026-31251HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31250HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31249HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31248HIGH7.5Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and val...
CVE-2026-7819HIGH8.1Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now