2026 CVE Vulnerabilities

55,422 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3854HIGH8.8An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an ...
CVE-2026-3847HIGH8.8Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-3845HIGH8.8Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Fire...
CVE-2026-3483HIGH7.8An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei...
CVE-2026-3315HIGH7.8Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R...
CVE-2026-31796HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-31795HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-31792HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30987HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30985HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30983HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30979HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30978HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30958HIGH8.6OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal...
CVE-2026-30945HIGH7.1StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi...
CVE-2026-30944HIGH8.8StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_ap...
CVE-2026-30941HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 ...
CVE-2026-30939HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 ...
CVE-2026-30933HIGH7.5FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio...
CVE-2026-30928HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint ret...
CVE-2026-2724HIGH7.2The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr...
CVE-2026-2339HIGH7.5Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li...
CVE-2026-2273HIGH8.2CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untr...
CVE-2026-26738HIGH7.8Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary c...
CVE-2026-26148HIGH8.1External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now