2026 CVE Vulnerabilities

56,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64878CRITICAL9.9Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting ...
CVE-2026-64617LOW3.8Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL ...
CVE-2026-64616LOW3.3Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL...
CVE-2026-64615LOW3.3Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL o...
CVE-2026-64614LOW3.8Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o...
CVE-2026-64613MEDIUM6.2Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL...
CVE-2026-59147CRITICAL9.8Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i...
CVE-2026-59146HIGH7.8Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin...
CVE-2026-59145CRITICAL9.1Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i...
CVE-2026-59144CRITICAL9.8Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin...
CVE-2026-59143MEDIUM6.3Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offse...
CVE-2026-56852HIGH7.5A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
CVE-2026-56146MEDIUM5.4Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configur...
CVE-2026-56145MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-56144MEDIUM6.5Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl...
CVE-2026-50759HIGH7.5An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan...
CVE-2026-50758HIGH8.1Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c...
CVE-2026-50757HIGH7.8Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod...
CVE-2026-50756HIGH7.5An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro...
CVE-2026-50755CRITICAL9.8An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar...
CVE-2026-49092MEDIUM4.3Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v...
CVE-2026-47671MEDIUM5.4Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c...
CVE-2026-47667HIGH7.5CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i...
CVE-2026-46600HIGH7.5Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
CVE-2026-46403MEDIUM6.3Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now