2026 CVE Vulnerabilities

55,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52439CRITICAL9.8An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p...
CVE-2026-50103HIGH7.1A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to cra...
CVE-2026-50039HIGH8.7The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corru...
CVE-2026-50032HIGH8.7A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to ...
CVE-2026-49035CRITICAL9.2The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execu...
CVE-2026-47724CRITICAL9.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/...
CVE-2026-47723HIGH7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none o...
CVE-2026-39155MEDIUM6.5Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name ...
CVE-2026-38764HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne...
CVE-2026-34496HIGH7.1Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before...
CVE-2026-21655HIGH8.7Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and J...
CVE-2026-21653HIGH7.2Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forger...
CVE-2026-16796HIGH8.4Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo...
CVE-2026-16002HIGH8.8The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process an...
CVE-2026-15981CRITICAL9.8The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a...
CVE-2026-15968MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr...
CVE-2026-15967CRITICAL9.8Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2...
CVE-2026-15966CRITICAL9.8Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue af...
CVE-2026-15630CRITICAL9.9A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any...
CVE-2026-10697CRITICAL9.8Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,...
CVE-2026-65706HIGH8.5FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allo...
CVE-2026-65705HIGH7.8FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that all...
CVE-2026-65704HIGH7.8FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by sup...
CVE-2026-65703HIGH8.5FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows rem...
CVE-2026-64785MEDIUM5.3SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now