2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-100504HIGH7Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 ...
CVE-2026-96795HIGH8.8Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py acc...
CVE-2026-57449HIGH7.1Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authe...
CVE-2026-88003HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-71483HIGH8.5Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected b...
CVE-2026-100419HIGH7gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that al...
CVE-2026-91765HIGH7.5cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated at...
CVE-2026-57443HIGH7.5SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4...
CVE-2026-10758HIGH7.5Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap...
CVE-2026-100391HIGH8.2MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing a...
CVE-2026-100390HIGH7.4Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded...
CVE-2026-100389HIGH8.1GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment ha...
CVE-2026-100387HIGH8.1pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization tha...
CVE-2026-100369HIGH8.4CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs...
CVE-2026-5267HIGH7.5Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API tha...
CVE-2026-100372HIGH7.2ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authent...
CVE-2026-100368HIGH8.4CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide spe...
CVE-2026-100310HIGH7GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environmen...
CVE-2026-100208HIGH7.5Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ...
CVE-2026-97060HIGH7.2X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to m...
CVE-2026-84465HIGH7.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signa...
CVE-2026-84464HIGH7.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source featur...
CVE-2026-55214HIGH8.5GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store...
CVE-2026-53629HIGH7.1GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ ...
CVE-2026-53626HIGH7.1GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now