2026 CVE Vulnerabilities

56,359 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24407HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24406HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24405HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers...
CVE-2026-24404HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v...
CVE-2026-24403HIGH8.8iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v...
CVE-2026-24136HIGH7.5Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.2...
CVE-2026-22995HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_wor...
CVE-2026-22984HIGH7.1In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in h...
CVE-2026-22980HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to ...
CVE-2026-24635HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-24624HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforu...
CVE-2026-24623HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforu...
CVE-2026-24609HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-24608HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-24572HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel...
CVE-2026-24538HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-24531HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-0994HIGH7.5A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recur...
CVE-2026-22273HIGH8.8Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default C...
CVE-2026-22271HIGH7.5Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi...
CVE-2026-0603HIGH8.3A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerab...
CVE-2026-0796HIGH8.8ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-0795HIGH8.8ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-0790HIGH7.5ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote ...
CVE-2026-0789HIGH7.5ALGO 8180 IP Audio Alerter Web UI Inclusion of Authentication Cookie in Response Body Information Disclosure Vulnerabili...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now