2026 CVE Vulnerabilities
53,539 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64835 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l... |
| CVE-2026-64834 | HIGH | 8.7 | 0.5% | Jul 22, 2026 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp... |
| CVE-2026-64833 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker... |
| CVE-2026-64832 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc... |
| CVE-2026-16157 | HIGH | 7.8 | 0.1% | Jul 22, 2026 | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In... |
| CVE-2026-7328 | MEDIUM | 6.8 | — | Jul 22, 2026 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM... |
| CVE-2026-65013 | HIGH | 8.8 | 0.5% | Jul 22, 2026 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a... |
| CVE-2026-65012 | MEDIUM | 6.3 | 0.4% | Jul 22, 2026 | InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo... |
| CVE-2026-65011 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de... |
| CVE-2026-64831 | HIGH | 8.8 | 0.5% | Jul 22, 2026 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder tha... |
| CVE-2026-64830 | HIGH | 8.8 | 0.4% | Jul 22, 2026 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo... |
| CVE-2026-16615 | MEDIUM | 6.8 | 0.3% | Jul 22, 2026 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, ... |
| CVE-2026-64828 | MEDIUM | 6.1 | 0.2% | Jul 22, 2026 | Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac... |
| CVE-2026-49499 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera... |
| CVE-2026-46738 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-46737 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-44276 | MEDIUM | 4.4 | 0.1% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth... |
| CVE-2026-40714 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig... |
| CVE-2026-40712 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-16607 | HIGH | 8.5 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-16606 | CRITICAL | 9.8 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-16552 | — | — | — | Jul 22, 2026 | Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of t... |
| CVE-2026-48029 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image... |
| CVE-2026-2395 | CRITICAL | 9.8 | 0.4% | Jul 22, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info... |
| CVE-2026-14985 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now