2026 CVE Vulnerabilities

55,919 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13055HIGH7.1The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)...
CVE-2026-3482MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6....
CVE-2026-22049HIGH8.8ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera...
CVE-2026-16624CRITICAL9.6Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on...
CVE-2026-65650MEDIUM4.3Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
CVE-2026-64835HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l...
CVE-2026-64834HIGH8.7FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp...
CVE-2026-64833HIGH7.1FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker...
CVE-2026-64832HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc...
CVE-2026-16157HIGH7.8Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In...
CVE-2026-7328MEDIUM6.8Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM...
CVE-2026-65013HIGH8.8Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a...
CVE-2026-65012MEDIUM6.3InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo...
CVE-2026-65011MEDIUM5.3Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de...
CVE-2026-64831HIGH8.8FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder tha...
CVE-2026-64830HIGH8.8FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo...
CVE-2026-16615MEDIUM6.8A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, ...
CVE-2026-64828MEDIUM6.1Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac...
CVE-2026-49499HIGH8.8Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera...
CVE-2026-46738HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-46737HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-44276MEDIUM4.4Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth...
CVE-2026-40714HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig...
CVE-2026-40712HIGH7.2Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the...
CVE-2026-16607HIGH8.5A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now