2026 CVE Vulnerabilities

53,351 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66037MEDIUM5.5FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d...
CVE-2026-66036HIGH8.8FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter...
CVE-2026-62835HIGH7.5Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-57531MEDIUM5.4Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo...
CVE-2026-57530MEDIUM5.4Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk...
CVE-2026-54342HIGH8.1In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste...
CVE-2026-48037MEDIUM6.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48036HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48035HIGH7.1Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48034HIGH8.5Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48033HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48032HIGH8.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48021CRITICAL9.1In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba...
CVE-2026-17107HIGH8.5A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes...
CVE-2026-66035HIGH7.7libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a...
CVE-2026-66034HIGH7.7libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S...
CVE-2026-66033HIGH8.7libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss...
CVE-2026-66032HIGH8.8libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src...
CVE-2026-65711HIGH8.6sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t...
CVE-2026-65710HIGH7.1sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P...
CVE-2026-65709HIGH8.7sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo...
CVE-2026-65708HIGH8.6sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated ...
CVE-2026-65707HIGH8.5Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar...
CVE-2026-65623HIGH8.7Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via C...
CVE-2026-66027HIGH8.7Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now