2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61378MEDIUM6.8A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to...
CVE-2026-60073MEDIUM5.9An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB ...
CVE-2026-57896MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-55173HIGH8.1WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because ...
CVE-2026-53410HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...
CVE-2026-53409HIGH7.8Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct ...
CVE-2026-44023HIGH8.6Docling Core defines core data types and transformations for the document processing application Docling. In versions 1....
CVE-2026-44019HIGH8.1Docling Core defines core data types and transformations for the document processing application Docling. In versions 2....
CVE-2026-38158CRITICAL9.8A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc...
CVE-2026-36425MEDIUM6.5An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user...
CVE-2026-33731MEDIUM6.5WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut...
CVE-2026-33692HIGH7.5WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through ...
CVE-2026-11889HIGH7.1SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at...
CVE-2026-63397HIGH7.1remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t...
CVE-2026-63089CRITICAL9.3WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation...
CVE-2026-62994LOW3.7CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD...
CVE-2026-62963HIGH8.7Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr...
CVE-2026-62309HIGH7.5CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when...
CVE-2026-62299MEDIUM5.3CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ...
CVE-2026-62290HIGH7.3cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc...
CVE-2026-61718MEDIUM5.4bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w...
CVE-2026-61389HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-60140MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-60063HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-55629HIGH8.7Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now