2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16356CRITICAL9.8Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-16355CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-16354HIGH7.5Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-16353CRITICAL9.8Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38...
CVE-2026-16352CRITICAL9.8Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15...
CVE-2026-16351CRITICAL9.8Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Fire...
CVE-2026-16350CRITICAL9.8Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ...
CVE-2026-16349CRITICAL9.8Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115...
CVE-2026-65009MEDIUM5.3OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th...
CVE-2026-65008CRITICAL9.8Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/...
CVE-2026-65007CRITICAL9.6The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the pl...
CVE-2026-64628MEDIUM5.4Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s...
CVE-2026-64627MEDIUM6.9Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit...
CVE-2026-60080HIGH7.3Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13....
CVE-2026-59845MEDIUM5.9A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin...
CVE-2026-59844MEDIUM6.5A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng...
CVE-2026-59843MEDIUM6.5A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN...
CVE-2026-59842MEDIUM5.3A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than...
CVE-2026-1617CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica...
CVE-2026-16461MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v...
CVE-2026-64606CRITICAL9.8Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb...
CVE-2026-64609CRITICAL9.1Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVa...
CVE-2026-64608CRITICAL9.8Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa...
CVE-2026-62415CRITICAL9.1Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe...
CVE-2026-1771HIGH7.2The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now