2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48374HIGH7.8Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th...
CVE-2026-47726HIGH7.1nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-18107HIGH7.8A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid...
CVE-2026-16771HIGH8.8In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on ...
CVE-2026-16496HIGH8.9The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t...
CVE-2026-15992HIGH8.8The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3....
CVE-2026-14869HIGH8.6The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT...
CVE-2026-59933HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-59931HIGH7.7PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-54635HIGH7.5pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2....
CVE-2026-48388HIGH8.6Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ...
CVE-2026-48372HIGH7.8Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i...
CVE-2026-67185HIGH8.7TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi...
CVE-2026-67184HIGH8.7TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-67183HIGH8.7TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me...
CVE-2026-67182HIGH7.5Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce...
CVE-2026-54609HIGH8.6QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle...
CVE-2026-54605HIGH7.2OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:...
CVE-2026-54603HIGH8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0...
CVE-2026-54345HIGH7.5gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes...
CVE-2026-54332HIGH7.5gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec...
CVE-2026-18084HIGH8.6Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB...
CVE-2026-16313HIGH7.6A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification ...
CVE-2026-66754HIGH8.2Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all...
CVE-2026-66749HIGH7.1Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now