2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-28926HIGH7A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1...
CVE-2026-28912HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A...
CVE-2026-28896HIGH7.7The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8....
CVE-2026-66015HIGH7.2An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c...
CVE-2026-65921HIGH8.8A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou...
CVE-2026-65617HIGH8.8A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia...
CVE-2026-65616HIGH8.8Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra...
CVE-2026-56748HIGH8.8Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe...
CVE-2026-56747HIGH8.8Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r...
CVE-2026-42017HIGH8.8An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use...
CVE-2026-42016HIGH8.8JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida...
CVE-2026-66759HIGH7.1A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl...
CVE-2026-66758HIGH7.8A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca...
CVE-2026-16481HIGH8.4A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch...
CVE-2026-12383HIGH7.5A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control...
CVE-2026-10682HIGH7.8The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a s...
CVE-2026-66028HIGH7.1Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe...
CVE-2026-64642HIGH8.2Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque...
CVE-2026-64641HIGH7.5Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59239HIGH8.6Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe...
CVE-2026-55578HIGH8.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin...
CVE-2026-54540HIGH8.8Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term...
CVE-2026-17568HIGH8.8Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm...
CVE-2026-66731HIGH8.7facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser...
CVE-2026-66730HIGH8.7facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now