2026 CVE Vulnerabilities

51,132 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8092HIGH8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed ...
CVE-2026-8090HIGH7.3Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, ...
CVE-2026-6002HIGH8.8Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te...
CVE-2026-5784HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-42285HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, a...
CVE-2026-41644HIGH7.1monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) ...
CVE-2026-41643HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4....
CVE-2026-41642HIGH7.5GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a...
CVE-2026-3953HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In...
CVE-2026-33588HIGH8.1Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr...
CVE-2026-28201HIGH7.8An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo...
CVE-2026-6805HIGH7.5Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf...
CVE-2026-44407HIGH7.5A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti...
CVE-2026-4430HIGH7.8Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc...
CVE-2026-44406HIGH7.8ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM...
CVE-2026-8063HIGH7.1An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When ...
CVE-2026-7252HIGH8.1The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress...
CVE-2026-6692HIGH8.8The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_...
CVE-2026-4348HIGH7.5The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_...
CVE-2026-41641HIGH7.2NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41413HIGH7.7Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ...
CVE-2026-41143HIGH8.8YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi...
CVE-2026-41139HIGH8.8Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary...
CVE-2026-44602HIGH7.5Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
CVE-2026-44601HIGH7.5Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now