2026 CVE Vulnerabilities

51,120 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33814HIGH7.5When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei...
CVE-2026-33811HIGH7.5When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a...
CVE-2026-8086HIGH7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file f...
CVE-2026-8083HIGH7.3A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the...
CVE-2026-44244HIGH7.8GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value...
CVE-2026-44243HIGH7.1GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPyt...
CVE-2026-42215HIGH8.8GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP...
CVE-2026-42214HIGH7.8Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom...
CVE-2026-41906HIGH7.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change ...
CVE-2026-41905HIGH7.7FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san...
CVE-2026-41904HIGH7.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with...
CVE-2026-41653HIGH7BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit...
CVE-2026-6973HIGH7.2An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic...
CVE-2026-5786HIGH8.8An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote...
CVE-2026-44349HIGH7.1Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda...
CVE-2026-42011HIGH7.4A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p...
CVE-2026-41688HIGH7.7Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ...
CVE-2026-41654HIGH8.1Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de...
CVE-2026-41505HIGH8.7RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation ...
CVE-2026-41422HIGH8.3Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an...
CVE-2026-41554HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder all...
CVE-2026-41490HIGH8.3Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster C...
CVE-2026-30495HIGH8.8The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP...
CVE-2026-8093HIGH8.1Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-8092HIGH8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now