2026 CVE Vulnerabilities

55,807 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65705HIGH7.8FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that all...
CVE-2026-65704HIGH7.8FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by sup...
CVE-2026-65703HIGH8.5FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows rem...
CVE-2026-64785MEDIUM5.3SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r...
CVE-2026-63359CRITICAL9.8The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att...
CVE-2026-60122HIGH8.5gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha...
CVE-2026-48013MEDIUM4.1Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint ...
CVE-2026-48012MEDIUM4.3Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO ...
CVE-2026-47722HIGH8.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `inter...
CVE-2026-47670CRITICAL9.4DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio...
CVE-2026-47669CRITICAL9.3DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api...
CVE-2026-25800HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and...
CVE-2026-15212HIGH8.8The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43...
CVE-2026-12353MEDIUM5.3An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se...
CVE-2026-65010MEDIUM6.6Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a...
CVE-2026-63765HIGH8.8Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau...
CVE-2026-16756HIGH8.7Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o...
CVE-2026-15687LOW2.4A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ...
CVE-2026-6516CRITICAL10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the...
CVE-2026-65920MEDIUM5.3Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_...
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now