2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-43753MEDIUM4.6An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO...
CVE-2026-43744MEDIUM5.5An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-43739MEDIUM5.5An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26....
CVE-2026-43738MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8....
CVE-2026-43714MEDIUM5.5The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia...
CVE-2026-43665MEDIUM5.5This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1...
CVE-2026-28932MEDIUM5.5A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f...
CVE-2026-28900MEDIUM5.5A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma...
CVE-2026-28849MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malici...
CVE-2026-20672MEDIUM5.5An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7....
CVE-2026-12001MEDIUM5.2A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-...
CVE-2026-66018MEDIUM6.5Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor...
CVE-2026-65925MEDIUM6.5A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret...
CVE-2026-65924MEDIUM6.5JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (...
CVE-2026-65923MEDIUM6.8A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository...
CVE-2026-65922MEDIUM5.4An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc...
CVE-2026-65618MEDIUM6.5Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized ...
CVE-2026-64649MEDIUM6.5Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr...
CVE-2026-64648MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59729MEDIUM5.1Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp...
CVE-2026-66757MEDIUM5.5A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor...
CVE-2026-66031MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-64647MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64646MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-17612MEDIUM6.9Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now