2026 CVE Vulnerabilities

55,842 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27571HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling ...
CVE-2026-27521HIGH7.5Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun...
CVE-2026-27520HIGH8.7Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side c...
CVE-2026-27519HIGH8.7Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded i...
CVE-2026-27516HIGH8.6Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext withi...
CVE-2026-23678HIGH8.8Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerabilit...
CVE-2026-3102HIGH8.8A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the fil...
CVE-2026-3101HIGH8.8A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping ...
CVE-2026-27732HIGH8.1WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a...
CVE-2026-27584HIGH7.5Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualB...
CVE-2026-27483HIGH8.8MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a p...
CVE-2026-27208HIGH7.8bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involvi...
CVE-2026-2803HIGH7.5Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and ...
CVE-2026-2801HIGH7.5Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and ...
CVE-2026-2798HIGH8.8Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVE-2026-2794HIGH7.5Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixe...
CVE-2026-2783HIGH7.5Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed i...
CVE-2026-2769HIGH8.8Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fir...
CVE-2026-2460HIGH8.1A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of ...
CVE-2026-2459HIGH8.1A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of direc...
CVE-2026-1773HIGH7.5IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is on...
CVE-2026-2664HIGH7.8An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows,...
CVE-2026-3067HIGH8.8A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the...
CVE-2026-3066HIGH8.8A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer...
CVE-2026-3091HIGH7.3An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now