2026 CVE Vulnerabilities

56,211 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-20615HIGH7.8A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Seq...
CVE-2026-20614HIGH7.8A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma ...
CVE-2026-20611HIGH7.8An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS ...
CVE-2026-20610HIGH7.8This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able...
CVE-2026-20606HIGH7.1This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 ...
CVE-2026-1669HIGH7.5Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp...
CVE-2026-26029HIGH7.5sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability ex...
CVE-2026-26158HIGH7A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di...
CVE-2026-26157HIGH7A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf...
CVE-2026-26010HIGH7.6OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines ...
CVE-2026-25990HIGH7.5Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a...
CVE-2026-25924HIGH8.4Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulner...
CVE-2026-25759HIGH8.7Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnera...
CVE-2026-2321HIGH8.8Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage...
CVE-2026-2319HIGH7.5Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in spe...
CVE-2026-2315HIGH8.8Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially ...
CVE-2026-2314HIGH8.8Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit ...
CVE-2026-2313HIGH8.8Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corr...
CVE-2026-2361HIGH8PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary v...
CVE-2026-2360HIGH8PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom oper...
CVE-2026-25869HIGH7.5MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The app...
CVE-2026-1837HIGH7.5A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after ...
CVE-2026-2344HIGH8.6A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged use...
CVE-2026-2250HIGH7.5The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and exp...
CVE-2026-2337HIGH8.7A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now