2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16332HIGH7.3A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload...
CVE-2026-16331HIGH7.3A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/fu...
CVE-2026-16330HIGH7.3A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jqu...
CVE-2026-16329HIGH7.3A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/up...
CVE-2026-63728HIGH8.1Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence r...
CVE-2026-55833HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-55831HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-16327HIGH7.3A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_...
CVE-2026-15905HIGH7.8Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap cor...
CVE-2026-15904HIGH8.8Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user...
CVE-2026-15903HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitra...
CVE-2026-15902HIGH8.8Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-15901CRITICAL9.6Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap...
CVE-2026-15900CRITICAL9.6Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perfo...
CVE-2026-15899CRITICAL9.6Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially...
CVE-2026-64626MEDIUM6.4AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en...
CVE-2026-64625CRITICAL9.8AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-q...
CVE-2026-64624HIGH8.5FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the e...
CVE-2026-57852MEDIUM6.3Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att...
CVE-2026-57495HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, ...
CVE-2026-57494HIGH7.1AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-p...
CVE-2026-55550HIGH7.1NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide ...
CVE-2026-55544HIGH7.6NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose...
CVE-2026-52656CRITICAL9.8An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a...
CVE-2026-51385MEDIUM6.9An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now