2026 CVE Vulnerabilities

55,512 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30929HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-30926HIGH7.1SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu...
CVE-2026-30883HIGH7.8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28693HIGH8.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28691HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28494HIGH7.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-28432HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit...
CVE-2026-28431HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p...
CVE-2026-26982HIGH8.8Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dro...
CVE-2026-3288HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati...
CVE-2026-30240HIGH8.1Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path ...
CVE-2026-25045HIGH8.8Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of...
CVE-2026-25041HIGH7.2Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po...
CVE-2026-0846HIGH7.5A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea...
CVE-2026-30140HIGH7.5An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t...
CVE-2026-29023HIGH7.3Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled an...
CVE-2026-25866HIGH8.5MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExe...
CVE-2026-3038HIGH7.5The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st...
CVE-2026-2261HIGH7.5Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert...
CVE-2026-3815HIGH8.8A weakness has been identified in UTT HiPER 810G up to 1.7.7-1711. This affects the function strcpy of the file /goform/...
CVE-2026-3814HIGH8.8A security flaw has been discovered in UTT HiPER 810G up to 1.7.7-1711. Affected by this issue is the function strcpy of...
CVE-2026-3811HIGH8.8A vulnerability was found in Tenda FH1202 1.2.0.14(408). This impacts the function fromP2pListFilter of the file /goform...
CVE-2026-3810HIGH8.8A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpListClient of the file /...
CVE-2026-3809HIGH8.8A flaw has been found in Tenda FH1202 1.2.0.14(408). The impacted element is the function fromNatStaticSetting of the fi...
CVE-2026-3808HIGH8.8A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now