2026 CVE Vulnerabilities

56,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47685HIGH8.7FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47237HIGH8Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio...
CVE-2026-47143MEDIUM5.9Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR...
CVE-2026-46556MEDIUM6.5FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Req...
CVE-2026-45383MEDIUM6.9libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow...
CVE-2026-45382MEDIUM6.9libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_sl...
CVE-2026-44879HIGH7.2A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta...
CVE-2026-44878HIGH7.2A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r...
CVE-2026-30633HIGH7.5Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools...
CVE-2026-30631CRITICAL9.8An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers...
CVE-2026-16318MEDIUM6.9The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store th...
CVE-2026-16317HIGH8.3Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-mi...
CVE-2026-12139MEDIUM5.5Tanium addressed an information disclosure vulnerability in Connect.
CVE-2026-11925LOW2.7Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
CVE-2026-65069MEDIUM4Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_...
CVE-2026-65068LOW3.8Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_...
CVE-2026-65067LOW3.8Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL ...
CVE-2026-65066LOW3.8Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_E...
CVE-2026-65065MEDIUM5.5Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without ...
CVE-2026-65064LOW3.8Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL...
CVE-2026-65063LOW3.8Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EX...
CVE-2026-65062LOW3.8Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EX...
CVE-2026-65061LOW3.8Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL ...
CVE-2026-64880HIGH7.1Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper ...
CVE-2026-64879CRITICAL9.9A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now