2026 CVE Vulnerabilities

56,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13068MEDIUM4.3An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac...
CVE-2026-13067HIGH7.2When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v...
CVE-2026-13066HIGH7.1Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i...
CVE-2026-13065HIGH7.1A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator...
CVE-2026-13064HIGH7.1Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ...
CVE-2026-13063MEDIUM5.3An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem...
CVE-2026-13062HIGH7.1An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ...
CVE-2026-13061MEDIUM5.3An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi...
CVE-2026-13060HIGH7.1An authenticated user with limited read privileges may be able to access documents from collections they are not authori...
CVE-2026-13059HIGH8.6An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role...
CVE-2026-13058MEDIUM6.5An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf...
CVE-2026-13057MEDIUM6.5An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In...
CVE-2026-13056HIGH7.1Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object...
CVE-2026-13055HIGH7.1The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)...
CVE-2026-3482MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6....
CVE-2026-22049HIGH8.8ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera...
CVE-2026-16624CRITICAL9.6Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on...
CVE-2026-65650MEDIUM4.3Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
CVE-2026-64835HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l...
CVE-2026-64834HIGH8.7FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp...
CVE-2026-64833HIGH7.1FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker...
CVE-2026-64832HIGH8.8FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavc...
CVE-2026-16157HIGH7.8Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. In...
CVE-2026-7328MEDIUM6.8Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM...
CVE-2026-65013HIGH8.8Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now