2026 CVE Vulnerabilities

56,354 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24869HIGH8.8Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
CVE-2026-24831HIGH7.5Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ix...
CVE-2026-24828HIGH7.5Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: be...
CVE-2026-24827HIGH7.5Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs...
CVE-2026-24345HIGH8.8Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization che...
CVE-2026-21417HIGH7.2Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability. ...
CVE-2026-24817HIGH8.7Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with ...
CVE-2026-24813HIGH8.7NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerabilit...
CVE-2026-24808HIGH8.3Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with pr...
CVE-2026-24344HIGH7.3Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and ...
CVE-2026-21721HIGH8.1The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac...
CVE-2026-21720HIGH7.5Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10...
CVE-2026-1465HIGH8.7Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in anyrtcIO-Community anyRTC-RTMP-...
CVE-2026-21408HIGH7.3beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely...
CVE-2026-24486HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exi...
CVE-2026-24480HIGH8.7QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actio...
CVE-2026-24478HIGH7.2AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-24477HIGH7.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-1449HIGH7.3A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Loa...
CVE-2026-1448HIGH7.3A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_ma...
CVE-2026-24470HIGH8.1Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an...
CVE-2026-23864HIGH7.5Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser...
CVE-2026-0810HIGH7.1A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid no...
CVE-2026-24440HIGH8.8Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed thr...
CVE-2026-24430HIGH7.5Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now