2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5491HIGH7.5DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo...
CVE-2026-5490HIGH8.8DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privi...
CVE-2026-5487HIGH7.5DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo...
CVE-2026-5057HIGH7.5ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attacke...
CVE-2026-5056HIGH7.8GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote atta...
CVE-2026-18022HIGH8.8Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, w...
CVE-2026-15975HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-13268HIGH7.8G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows ...
CVE-2026-12436HIGH8.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-12357HIGH7.2Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability ...
CVE-2026-67428HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi...
CVE-2026-67427HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable ...
CVE-2026-67425HIGH8.6Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys ...
CVE-2026-67424HIGH8.5Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht...
CVE-2026-67201HIGH8.6V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows...
CVE-2026-59898HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,...
CVE-2026-2482HIGH8.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c...
CVE-2026-16328HIGH8.6In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing ...
CVE-2026-12935HIGH8.7The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b...
CVE-2026-8497HIGH7.4Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0...
CVE-2026-59901HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-59899HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-40272HIGH7Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k...
CVE-2026-14266HIGH7.87-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-8339HIGH8.7A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now