2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40583HIGH8.2UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vo...
CVE-2026-40568HIGH8.5FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripti...
CVE-2026-38834HIGH7.3Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via th...
CVE-2026-24189HIGH8.2NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds re...
CVE-2026-24177HIGH7.7NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ...
CVE-2026-21571HIGH8.8This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11....
CVE-2026-37748HIGH7.2Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php a...
CVE-2026-5789HIGH7.8Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execut...
CVE-2026-3298HIGH8.8The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat...
CVE-2026-31019HIGH8.8In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict...
CVE-2026-31018HIGH8.8In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not appl...
CVE-2026-6784HIGH7.5Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption a...
CVE-2026-6782HIGH7.5Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6781HIGH7.5Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 15...
CVE-2026-6780HIGH7.5Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 15...
CVE-2026-6776HIGH7.8Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ...
CVE-2026-6773HIGH7.5Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150...
CVE-2026-6772HIGH7.5Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ES...
CVE-2026-6769HIGH8.8Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunder...
CVE-2026-6766HIGH7.5Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ES...
CVE-2026-6761HIGH8.8Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund...
CVE-2026-6759HIGH7.5Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderb...
CVE-2026-6758HIGH7.5Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150...
CVE-2026-6756HIGH7.5Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
CVE-2026-6754HIGH7.5Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now