2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31386HIGH8.6OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An a...
CVE-2026-2923HIGH7.8GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attack...
CVE-2026-2922HIGH7.8GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2026-2921HIGH7.8GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ...
CVE-2026-2920HIGH7.8GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-2493HIGH7.5IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke...
CVE-2026-28522HIGH7.1arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att...
CVE-2026-28521HIGH7.7arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a...
CVE-2026-28520HIGH8.6arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W...
CVE-2026-28519HIGH8.8arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An...
CVE-2026-26133HIGH7.1AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-25083HIGH8.7GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg...
CVE-2026-24458HIGH7.5Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,...
CVE-2026-20999HIGH7.5Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged...
CVE-2026-20990HIGH8.1Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attacker...
CVE-2026-1947HIGH7.5The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Referen...
CVE-2026-0977HIGH7.1IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope...
CVE-2026-4111HIGH7.5A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive...
CVE-2026-4092HIGH8.8Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic...
CVE-2026-3999HIGH8.8A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability...
CVE-2026-3910HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar...
CVE-2026-3909HIGH8.8Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m...
CVE-2026-3873HIGH7.2Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs....
CVE-2026-3045HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces...
CVE-2026-32597HIGH7.5PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now