2026 CVE Vulnerabilities

53,635 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30949HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30947HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30946HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alph...
CVE-2026-30837HIGH7.5Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi...
CVE-2026-0124HIGH7.8There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ...
CVE-2026-0123HIGH8.4In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds...
CVE-2026-0122HIGH8.4In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code exe...
CVE-2026-0118HIGH8.4In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalati...
CVE-2026-0117HIGH8.4In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could...
CVE-2026-0112HIGH7.4In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local es...
CVE-2026-0109HIGH7.5In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This cou...
CVE-2026-0107HIGH8.4In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. Th...
CVE-2026-2713HIGH7.8IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code ...
CVE-2026-29174HIGH8.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in ...
CVE-2026-29172HIGH8.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL In...
CVE-2026-28495HIGH8.8GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo...
CVE-2026-27825HIGH8MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0....
CVE-2026-26330HIGH7.5Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit f...
CVE-2026-26310HIGH7.5Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge...
CVE-2026-26308HIGH8.2Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Rol...
CVE-2026-27826HIGH8.2MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0....
CVE-2026-27280HIGH7.8DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr...
CVE-2026-27279HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i...
CVE-2026-27277HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-27276HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now