2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-67194HIGH7.1Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process...
CVE-2026-64560HIGH7.8In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader ...
CVE-2026-64559HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl ...
CVE-2026-64558HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler imple...
CVE-2026-54727HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink ...
CVE-2026-54693HIGH8.2ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4...
CVE-2026-54574HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain ta...
CVE-2026-18255HIGH7.2A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo...
CVE-2026-54079HIGH8.7veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30...
CVE-2026-54078HIGH8.7veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve...
CVE-2026-16543HIGH7.1Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr...
CVE-2026-16465HIGH7.1A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili...
CVE-2026-16463HIGH7.8A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m...
CVE-2026-15228HIGH7.1Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust...
CVE-2026-66723HIGH7MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ...
CVE-2026-65947HIGH7.3Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65886HIGH7.5Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut...
CVE-2026-59247HIGH7.6Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo...
CVE-2026-54666HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54664HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54662HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-...
CVE-2026-54661HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat...
CVE-2026-54660HIGH7.4swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol...
CVE-2026-12703HIGH8TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti...
CVE-2026-67216HIGH7.5cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now