2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3442HIGH7.1A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, ...
CVE-2026-3441HIGH7.1A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in t...
CVE-2026-3110HIGH8.7Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/...
CVE-2026-3086HIGH7.8GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-3085HIGH8.8GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote ...
CVE-2026-3084HIGH7.8GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2026-3083HIGH8.8GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2026-3082HIGH7.8GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-3081HIGH7.8GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2026-3023HIGH8.8Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa...
CVE-2026-3020HIGH8.6Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user...
CVE-2026-32775HIGH7.8libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 s...
CVE-2026-32729HIGH8.8Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor...
CVE-2026-32720HIGH7.1The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met...
CVE-2026-32708HIGH8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack ...
CVE-2026-32706HIGH8.1PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari...
CVE-2026-32628HIGH8.8AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32627HIGH8.1cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib cl...
CVE-2026-32617HIGH7.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32616HIGH8.2Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] witho...
CVE-2026-32614HIGH7.5Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial crypto...
CVE-2026-32600HIGH8.2xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes e...
CVE-2026-32594HIGH7.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 ...
CVE-2026-32314HIGH7.5Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementati...
CVE-2026-32313HIGH8.2xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypt...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now